The post North Korea-Linked Group Behind $270M Drift Hack, Six-Month Plot Revealed appeared on BitcoinEthereumNews.com. What initially appeared to be a sudden exploitThe post North Korea-Linked Group Behind $270M Drift Hack, Six-Month Plot Revealed appeared on BitcoinEthereumNews.com. What initially appeared to be a sudden exploit

North Korea-Linked Group Behind $270M Drift Hack, Six-Month Plot Revealed

2026/04/07 14:20
Okuma süresi: 5 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

What initially appeared to be a sudden exploit has now been revealed as a long-term, highly coordinated operation. Drift Protocol has disclosed that the $270 million hack was the result of a six-month infiltration campaign, allegedly tied to North Korean state-linked actors.

Rather than exploiting a simple vulnerability, the attackers built trust slowly, posing as a legitimate quantitative trading firm and embedding themselves within the ecosystem. Their approach went beyond digital deception. They engaged contributors directly, attended crypto conferences, and established relationships that appeared credible at every level.

This was not a smash-and-grab attack. It was calculated, patient, and designed to bypass not just technical defenses but human trust.

First Contact Begins At Crypto Conferences

The operation reportedly began in fall 2025, when the attackers made first contact at a major crypto conference. At the time, there were no immediate red flags. The group presented themselves as technically proficient professionals with verifiable backgrounds.

They spoke the language of DeFi fluently, demonstrating a deep understanding of Drift’s infrastructure and trading mechanisms. This level of expertise helped them blend in seamlessly with legitimate contributors and partners.

Soon after, communication moved to Telegram, where discussions continued over several months. These interactions were not rushed or suspicious. Instead, they mirrored the cadence of real collaboration, complete with technical discussions, strategic input, and ongoing engagement.

By maintaining consistency and credibility, the attackers gradually built trust within the community.

Building Trust Through Capital And Collaboration

By January 2026, the group had taken their involvement even further. They successfully onboarded an Ecosystem Vault and began participating in working sessions alongside Drift contributors.

Crucially, they also committed real capital, depositing over $1 million of their own funds into the protocol. This move reinforced their legitimacy, signaling that they had skin in the game.

Throughout February and March, members of the Drift ecosystem met these individuals in person across multiple countries. These face-to-face interactions added another layer of trust, making it even less likely that their intentions would be questioned.

By the time the attack was executed, the relationship between the attackers and the community had been established for nearly six months. It was a level of infiltration rarely seen in DeFi exploits.

Attack Execution Leveraged Sophisticated Entry Points

When the compromise finally occurred, it came through two highly targeted vectors.

The first involved a malicious TestFlight application, presented as a legitimate wallet product. This allowed the attackers to gain access to contributor devices under the guise of testing new tools.

The second vector exploited a known vulnerability in development environments like VSCode and Cursor. This flaw, flagged by the security community months earlier, enabled the execution of arbitrary code simply by opening a file.

Together, these methods allowed the attackers to compromise key devices without triggering immediate suspicion. Once inside, they were able to access sensitive workflows and approval mechanisms.

This stage of the operation highlights a critical shift in attack strategies. Instead of targeting smart contracts directly, attackers are increasingly focusing on the human and tooling layers surrounding them.

Multisig Weaknesses Exposed In Final Drain

With access secured, the attackers moved to the final phase: execution.

They obtained two multisig approvals, which were then used to authorize transactions. Notably, these transactions were pre-signed and left dormant for over a week, avoiding immediate detection.

On April 1, the attackers acted. In under a minute, approximately $270 million was drained from Drift’s vaults.

The speed and precision of the execution left little room for intervention. By the time the transactions were recognized, the funds had already been moved.

Drift has since warned that this incident exposes fundamental weaknesses in multisig-based security models. While multisig systems are designed to distribute trust, they remain vulnerable when signers themselves are compromised.

Links To North Korean State Actors Surface

Investigations into the attack have linked the operation to UNC4736, a group also known as AppleJeus or Citrine Sleet. This entity is widely associated with North Korean cyber operations and has been connected to previous high-profile exploits, including the Radiant Capital attack.

Interestingly, the individuals who interacted directly with Drift contributors were not identified as North Korean nationals. Instead, they appear to have been third-party intermediaries, equipped with carefully constructed identities designed to withstand scrutiny.

This layered approach makes attribution more complex while increasing the effectiveness of the operation. By separating the on-the-ground actors from the coordinating entity, the attackers were able to maintain plausible legitimacy throughout the infiltration.

A Wake-Up Call For DeFi Security Models

The Drift exploit is forcing the industry to confront an uncomfortable reality. Traditional security models, focused on code audits, smart contract vulnerabilities, and multisig protections, may not be enough to defend against adversaries willing to invest time, money, and human resources.

If attackers can spend six months building relationships, deploy capital to gain trust, and physically meet with teams, the attack surface extends far beyond code.

This raises a critical question for the DeFi ecosystem: what kind of security framework can detect and prevent this level of infiltration?

For now, the incident stands as one of the most sophisticated social-engineering-driven exploits in crypto history. It underscores the need for a more holistic approach to security, one that accounts for human behavior, operational processes, and the increasingly blurred lines between online and offline interactions.

As protocols continue to grow and attract more capital, the stakes will only rise. And as this case shows, the next generation of attacks may not come from anonymous wallets, but from trusted partners sitting across the table.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Source: https://nulltx.com/north-korea-linked-group-behind-270m-drift-hack-six-month-plot-revealed/

Piyasa Fırsatı
Drift Protocol Logosu
Drift Protocol Fiyatı(DRIFT)
$0,0436
$0,0436$0,0436
+9,00%
USD
Drift Protocol (DRIFT) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Riot Sells 500 BTC for $34.87 Million

Riot Sells 500 BTC for $34.87 Million

Riot Platforms has sold another 500 BTC worth approximately $34.87 million, bringing its total sales to 1,500 BTC—over $102 million—in just five days. Moves of
Paylaş
Coinfomania2026/04/07 19:02
Edges higher ahead of BoC-Fed policy outcome

Edges higher ahead of BoC-Fed policy outcome

The post Edges higher ahead of BoC-Fed policy outcome appeared on BitcoinEthereumNews.com. USD/CAD gains marginally to near 1.3760 ahead of monetary policy announcements by the Fed and the BoC. Both the Fed and the BoC are expected to lower interest rates. USD/CAD forms a Head and Shoulder chart pattern. The USD/CAD pair ticks up to near 1.3760 during the late European session on Wednesday. The Loonie pair gains marginally ahead of monetary policy outcomes by the Bank of Canada (BoC) and the Federal Reserve (Fed) during New York trading hours. Both the BoC and the Fed are expected to cut interest rates amid mounting labor market conditions in their respective economies. Inflationary pressures in the Canadian economy have cooled down, emerging as another reason behind the BoC’s dovish expectations. However, the Fed is expected to start the monetary-easing campaign despite the United States (US) inflation remaining higher. Investors will closely monitor press conferences from both Fed Chair Jerome Powell and BoC Governor Tiff Macklem to get cues about whether there will be more interest rate cuts in the remainder of the year. According to analysts from Barclays, the Fed’s latest median projections for interest rates are likely to call for three interest rate cuts by 2025. Ahead of the Fed’s monetary policy, the US Dollar Index (DXY), which tracks the Greenback’s value against six major currencies, holds onto Tuesday’s losses near 96.60. USD/CAD forms a Head and Shoulder chart pattern, which indicates a bearish reversal. The neckline of the above-mentioned chart pattern is plotted near 1.3715. The near-term trend of the pair remains bearish as it stays below the 20-day Exponential Moving Average (EMA), which trades around 1.3800. The 14-day Relative Strength Index (RSI) slides to near 40.00. A fresh bearish momentum would emerge if the RSI falls below that level. Going forward, the asset could slide towards the round level of…
Paylaş
BitcoinEthereumNews2025/09/18 01:23
Bitcoin Price Drops Below $66,000 as $251M in Longs Vanish

Bitcoin Price Drops Below $66,000 as $251M in Longs Vanish

The post Bitcoin Price Drops Below $66,000 as $251M in Longs Vanish appeared on BitcoinEthereumNews.com. Bitcoin ($BTC) plummeted below the critical $66,000 threshold
Paylaş
BitcoinEthereumNews2026/04/02 22:09

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!