Close Menu
CryptoDispatchDaily.comCryptoDispatchDaily.com
    What's Hot

    Russia is blocking Telegram while its crypto community struggles to find alternatives

    April 1, 2026

    OpenAI launches smart contract security evaluation system

    February 19, 2026

    Why This Expert Is Predicting A $10,000 Base Price For XRP

    February 19, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    Facebook X (Twitter) Instagram
    CryptoDispatchDaily.comCryptoDispatchDaily.com
    • News

      Bitcoin Eyes $78K Breakout as Momentum Indicators Remain Neutral

      May 20, 2026

      Analyst Says Roadmap For Bitcoin To Reach $500,000 Is Complete, Here’s Why

      May 19, 2026

      Harvard cuts stake in BlackRock’s BTC ETF as crypto deleverage extends into Q1

      May 17, 2026

      Can BNB price break above $750 as double bottom pattern forms?

      May 15, 2026

      Casper Network Plans Quantum-Safe Keys in 2027 to Protect Tokenized Assets

      May 14, 2026
    • Technology

      Proof of Work vs Proof of Stake – Which consensus mechanism is better?

      May 20, 2026

      Stellar Price Prediction Turns Bullish as XLM Eyes Breakout Toward $0.68

      May 18, 2026

      DeFi meets AI – How smart protocols are revolutionizing finance

      May 17, 2026

      ONDO’s Three-Product Protocol Hits $3.778B TVL as Institutional Giants Join Settlement Pilots

      May 16, 2026

      Quantum-resistant crypto – Bitcoin, Ethereum, and preparing blockchain for future

      May 15, 2026
    • Learn/Guide

      Wadoozie ($WADZ): The Ethereum Memecoin With a 48-State Tour and Hidden Token Rewards

      May 7, 2026

      How to Optimize Company Operational Costs: A Manual on Modern Payment Ecosystems

      March 6, 2026

      6 Best Citizenship by Investment Programs for 2026

      February 23, 2026

      Strategies to Conquering Risk in Crypto Trading

      February 18, 2026

      What is GameFi? How to Play and Earn Crypto in 2025

      February 18, 2026
    • Regulation

      Poland Approves MiCA Law While Zondacrypto Probe Grows

      May 15, 2026

      UK Treasury Sees Digital Assets Reshaping Financial Markets and Payments

      May 14, 2026

      Labor and Banks Oppose Senate Crypto Clarity Act Bill

      May 13, 2026

      Senate Banking Panel to Debate CLARITY Act May 14

      May 12, 2026

      Coinbase, Kraken & Gemini Push Back on Senate Crypto Listing Rules

      May 10, 2026
    • Live Pricing Chart
    CryptoDispatchDaily.comCryptoDispatchDaily.com
    Home » Drift links $280 million exploit to six-month social engineering op run by suspected North Korean actors
    News

    Drift links $280 million exploit to six-month social engineering op run by suspected North Korean actors

    April 6, 20265 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Drift links $280 million exploit to six-month social engineering op run by suspected North Korean actors
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Drift Protocol on Saturday published its most detailed account yet of the April 1 exploit that drained approximately $280 million from the Solana-based perpetuals exchange, describing what the team called a “structured intelligence operation” that took roughly six months to stage.

    According to the update, the initial contact came in or around fall 2025, when individuals presenting as a quant trading firm approached Drift contributors at a major crypto conference and expressed interest in integrating on the protocol. A Telegram group was set up at that first meeting, and the same individuals continued meeting Drift contributors face-to-face at industry events across multiple countries over the following months.

    Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, filling out the standard strategy form, sitting through multiple working sessions with contributors, and depositing more than $1 million of their own capital. Drift said the behavior was consistent with how legitimate trading firms typically integrate with the protocol.

    Forensic review of affected devices and communication histories after the exploit pointed to that relationship as the probable intrusion path. Drift said the group’s Telegram chats and associated malicious software were scrubbed in the moments the attack went live.

    Two possible vectors

    Drift’s preliminary assessment identifies two candidate compromise methods. One contributor may have been infected after cloning a code repository the group shared under the pretext of deploying a frontend for their vault. A second contributor was induced to install a beta version of an app through Apple’s TestFlight build that the group described as their wallet product.

    For the repository path, Drift flagged a VS Code and Cursor vulnerability that security researchers had been publicly warning about between December 2025 and February 2026, in which simply opening a file, folder, or repository in the editor could silently execute arbitrary code with no user prompt.

    The exploit itself, as The Block previously reported, did not involve a smart contract bug. Drift has described it as a “novel attack involving durable nonces,” a legitimate Solana primitive that allows transactions to be pre-signed and executed later. The attacker obtained multisig approvals in advance, likely through social engineering or transaction misrepresentation, then used the pre-signed authorizations to seize Security Council administrative powers and drain the protocol in minutes.

    North Korea connection

    Drift said that with the support of the SEAL 911 team, it assesses with “medium-high confidence” that the operation was carried out by the same state-sponsored North Korean actors responsible for the $50 million Radiant Capital hack in October 2024, which Mandiant attributed to UNC4736, also known as AppleJeus or Citrine Sleet, a hacker group with ties to the country’s Reconnaissance General Bureau. 

    The link rests on both onchain and operational overlaps, according to Drift. Fund flows used to stage and test the Drift operation trace back to the Radiant attackers, and the personas deployed across the campaign have identifiable overlaps with known DPRK-linked activity, Drift said.

    Notably, Drift stressed that the individuals who appeared at conferences in person were not North Korean nationals. DPRK threat actors operating at this level are known to deploy third-party intermediaries to handle relationship-building work, the protocol said, and the profiles used in this operation had complete employment histories, public credentials, and professional networks designed to withstand counterparty due diligence.

    Mandiant, which Drift has engaged to lead the forensic investigation, has not formally attributed the Drift exploit. That determination is pending completed device forensics.

    Current state of Drift

    Drift said all remaining protocol functions have been frozen, the compromised wallets have been removed from the multisig, and attacker addresses have been flagged with exchanges and bridge operators. Onchain sleuth ZachXBT has separately criticized stablecoin issuer Circle for what he called a slow response, alleging the attacker bridged roughly 232 million USDC from Solana to Ethereum via CCTP over six hours without any funds being frozen.

    The Drift exploit is the largest DeFi hack of 2026 to date and ranks as the second-largest security incident in Solana’s history behind the $325 million Wormhole bridge attack in 2022.

    Drift credited independent researchers and SEAL 911 members Taylor Monahan, tanuki42_, pcaversaccio, and Nick Bax for their work identifying the actors, and urged any teams that believe they may have been targeted by the same group to contact SEAL 911 directly.

    “For real though – this is the most elaborate and targeted attack I think I’ve seen perpetrated by DPRK in the crypto space,” tanuki42_ wrote on X, in addition to warning that other protocols may have been targeted as well. “Recruiting multiple facilitators and then getting them to target specific people in real life at major crypto events is a wild tactic.”

    Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

    © 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Bitcoin Eyes $78K Breakout as Momentum Indicators Remain Neutral

    May 20, 2026

    Analyst Says Roadmap For Bitcoin To Reach $500,000 Is Complete, Here’s Why

    May 19, 2026

    Harvard cuts stake in BlackRock’s BTC ETF as crypto deleverage extends into Q1

    May 17, 2026

    Can BNB price break above $750 as double bottom pattern forms?

    May 15, 2026
    Top Posts

    Binance adds news features to Binance Junior to increase family crypto savings and learning

    February 19, 2026

    Worldcoin is Predicted to Drop to $0.245759 By Mar 26, 2026

    March 21, 2026

    Ledger Opens New York City Office to Scale US Expansion

    March 23, 2026

    Welcome to CryptoDispatchDaily.com! Your go-to source for fast, reliable updates from the ever-evolving world of cryptocurrency. Whether it's Bitcoin, altcoins, blockchain breakthroughs, or DeFi trends, we bring you timely insights, expert analysis, and key developments shaping the future of digital finance. Stay ahead with real-time crypto news and in-depth coverage.

    Top Insights

    Bitcoin Eyes $78K Breakout as Momentum Indicators Remain Neutral

    May 20, 2026

    Analyst Says Roadmap For Bitcoin To Reach $500,000 Is Complete, Here’s Why

    May 19, 2026

    Harvard cuts stake in BlackRock’s BTC ETF as crypto deleverage extends into Q1

    May 17, 2026
    Advertisement
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    © 2026. Designed by CryptoDispatchDaily.com.

    Type above and press Enter to search. Press Esc to cancel.