Drift links $280 million exploit to six-month social engineering op run by suspected North Korean actors
爆料中本聪
04-06 01:00
Ai Focus
With "medium-high" confidence, Drift and the SEAL 911 team assess the operation was run by the same North Korean actors behind the Radiant Capital hack.
Helpful
No.Help

Drift Protocol on Saturday published its most detailed account yet of the April 1 exploit that drained approximately $280 million from the Solana-based perpetuals exchange, describing what the team called a "structured intelligence operation" that took roughly six months to stage.

According to the update, the initial contact came in or around fall 2025, when individuals presenting as a quant trading firm approached Drift contributors at a major crypto conference and expressed interest in integrating on the protocol. A Telegram group was set up at that first meeting, and the same individuals continued meeting Drift contributors face-to-face at industry events across multiple countries over the following months.

Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, filling out the standard strategy form, sitting through multiple working sessions with contributors, and depositing more than $1 million of their own capital. Drift said the behavior was consistent with how legitimate trading firms typically integrate with the protocol.

Forensic review of affected devices and communication histories after the exploit pointed to that relationship as the probable intrusion path. Drift said the group's Telegram chats and associated malicious software were scrubbed in the moments the attack went live.

Two possible vectors

Drift's preliminary assessment identifies two candidate compromise methods. One contributor may have been infected after cloning a code repository the group shared under the pretext of deploying a frontend for their vault. A second contributor was induced to install a beta version of an app through Apple's TestFlight build that the group described as their wallet product.

For the repository path, Drift flagged a VS Code and Cursor vulnerability that security researchers had been publicly warning about between December 2025 and February 2026, in which simply opening a file, folder, or repository in the editor could silently execute arbitrary code with no user prompt.

The exploit itself, as The Block previously reported, did not involve a smart contract bug. Drift has described it as a "novel attack involving durable nonces," a legitimate Solana primitive that allows transactions to be pre-signed and executed later. The attacker obtained multisig approvals in advance, likely through social engineering or transaction misrepresentation, then used the pre-signed authorizations to seize Security Council administrative powers and drain the protocol in minutes.

North Korea connection

Drift said that with the support of the SEAL 911 team, it assesses with "medium-high confidence" that the operation was carried out by the same state-sponsored North Korean actors responsible for the $50 million Radiant Capital hack in October 2024, which Mandiant attributed to UNC4736, also known as AppleJeus or Citrine Sleet, a hacker group with ties to the country's Reconnaissance General Bureau. 

The link rests on both onchain and operational overlaps, according to Drift. Fund flows used to stage and test the Drift operation trace back to the Radiant attackers, and the personas deployed across the campaign have identifiable overlaps with known DPRK-linked activity, Drift said.

Notably, Drift stressed that the individuals who appeared at conferences in person were not North Korean nationals. DPRK threat actors operating at this level are known to deploy third-party intermediaries to handle relationship-building work, the protocol said, and the profiles used in this operation had complete employment histories, public credentials, and professional networks designed to withstand counterparty due diligence.

Mandiant, which Drift has engaged to lead the forensic investigation, has not formally attributed the Drift exploit. That determination is pending completed device forensics.

Current state of Drift

Drift said all remaining protocol functions have been frozen, the compromised wallets have been removed from the multisig, and attacker addresses have been flagged with exchanges and bridge operators. Onchain sleuth ZachXBT has separately criticized stablecoin issuer Circle for what he called a slow response, alleging the attacker bridged roughly 232 million USDC from Solana to Ethereum via CCTP over six hours without any funds being frozen.

The Drift exploit is the largest DeFi hack of 2026 to date and ranks as the second-largest security incident in Solana's history behind the $325 million Wormhole bridge attack in 2022.

Drift credited independent researchers and SEAL 911 members Taylor Monahan, tanuki42_, pcaversaccio, and Nick Bax for their work identifying the actors, and urged any teams that believe they may have been targeted by the same group to contact SEAL 911 directly.

"For real though - this is the most elaborate and targeted attack I think I've seen perpetrated by DPRK in the crypto space," tanuki42_ wrote on X, in addition to warning that other protocols may have been targeted as well. "Recruiting multiple facilitators and then getting them to target specific people in real life at major crypto events is a wild tactic."


Tip
$0
Like
0
Save
1
Views 184
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: During the sharp decline in South Korea, Upbit achieved a single-hour trading volume of 11.5 trillion Korean won
South Korean exchange Upbit saw a one-hour trading volume of 11.5 trillion Korean won during the flash crash period, with XRP having the highest trading proportion; the entire market cleared approximately 523 million US dollars in one hour.
Cryptonews
·2026-08-23 18:24:12
33
web3: South Korean crypto trading is picking up, with Upbit transaction volume soaring by 273%
South Korean crypto trading activity has picked up, with Upbit and Bithumb seeing a significant increase in 24-hour trading volume. XRP leads the Upbit trading rankings.
CoinPedia
·2026-08-23 17:32:39
30
UK retail sales fell by 0.5% in July: Why hasn't this single-month decline erased three months of growth?
The Office for National Statistics (ONS) of the UK announced on August 21 that retail sales in July fell by 0.5% month-on-month, marking the first monthly decline in three months; however, sales were still 1.6% higher than in July 2025. Over the three months to July, there was a 1.1% increase compared to the previous three months, and year-on-year, there was a 3.0% growth. These figures reflect both a short-term weakening and an improvement over a longer period. It is not appropriate to conclude that consumer spending has deteriorated based solely on the -0.5% figure, nor can one claim that household demand has strongly recovered just because of the year-on-year positive growth.
币百科
·2026-08-23 12:28:36
26
U.S. state-level unemployment rates remained stable in July: Despite a national rate of 4.1%, there is still significant regional variation.
The U.S. Bureau of Labor Statistics released state-level employment data on August 21: In July, the unemployment rate decreased significantly in 10 states, while it remained relatively stable in the remaining 40 states and the District of Columbia, with no state experiencing a statistically significant monthly increase. The national unemployment rate was 4.1%, showing little change both month-over-month and year-over-year. On the surface, these appear to be stable figures; however, non-farm employment did not show significant monthly changes in 48 states and the District of Columbia, with only Maryland seeing an increase and New Jersey experiencing a decrease, indicating that the geographical scope of employment expansion is still limited.
币百科
·2026-08-23 12:28:19
31
OpenAI Funds 14 Studies on the "Intelligent Era": Why Can't AI Policy Experiments Be Answered Only by Model Companies?
On August 17, OpenAI announced funding for 14 projects led by independent organizations, with themes focusing on economic opportunities and social resilience, continuing the discussions on "industrial policies in the intelligent era" initiated in April of this year. The selected projects cover areas such as labor force, education, local governance, social security, and technology diffusion. Compared to a single product launch, this arrangement is more worth observing from a methodological perspective: when AI affects not only software functionality but also employment structures, skill investments, and public institutions, it becomes difficult to determine who will bear the costs, how the benefits will be distributed, and which policies are effective in different regions, relying solely on internal research within model companies.
CoinMeta
·2026-08-23 12:28:00
28
View More