Drift says $270 million exploit was a six-month North Korean intelligence operation

DRIFT5,44%
RDNT2,34%
DEFI-20,99%

A six-month intelligence operation preceded the $270 million exploit of Drift Protocol and was carried out by a North Korean state-affiliated group, according to a detailed incident update published by the team earlier on Sunday.

The attackers first made contact around fall 2025 at a major crypto conference, presenting themselves as a quantitative trading firm looking to integrate with Drift.

They were technically fluent, had verifiable professional backgrounds, and understood how the protocol operated, Drift said. A Telegram group was established and what followed were months of substantive conversations around trading strategies and vault integrations, interactions that are standard for how trading firms onboard with DeFi protocols.

Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, held multiple working sessions with contributors, deposited over $1 million of their own capital, and built a functioning operational presence inside the ecosystem.

Drift contributors met individuals from the group face to face at multiple major industry conferences across several countries through February and March. By the time the attack launched on April 1, the relationship was nearly half a year old.

The compromise appears to have come through two vectors.

A second downloaded a TestFlight application, Apple’s platform for distributing pre-release apps that bypasses App Store security review, which the group presented as their wallet product.

For the repository vector, Drift pointed to a known vulnerability in VSCode and Cursor, two of the most widely used code editors in software development, that the security community had been flagging since late 2025, where simply opening a file or folder in the editor was sufficient to silently execute arbitrary code with no prompt or warning of any kind.

Once devices were compromised, the attackers had what they needed to obtain the two multisig approvals that enabled the durable nonce attack CoinDesk detailed earlier this week. Those pre-signed transactions sat dormant for more than a week before being executed on April 1, draining $270 million from the protocol’s vaults in under a minute.

The attribution points to UNC4736, a North Korean state-affiliated group also tracked as AppleJeus or Citrine Sleet, based on both on-chain fund flows tracing back to the Radiant Capital attackers and operational overlap with known DPRK-linked personas.

The individuals who appeared in person at conferences were not North Korean nationals, however. DPRK threat actors at this level are known to deploy third-party intermediaries with fully constructed identities, employment histories, and professional networks built to withstand due diligence.

Drift urged other protocols to audit access controls and treat every device touching a multisig as a potential target. The broader implication is uncomfortable for an industry that relies on multisig governance as its primary security model.

But if attackers are willing to spend six months and a million dollars building a legitimate presence inside an ecosystem, meet teams in person, contribute real capital, and wait, the question is what security model is designed to catch that.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Global Stocks Hit Record High as US-Iran Ceasefire Hopes Surge; Dollar Faces 17-Year Longest Losing Streak

Rising hopes for a US-Iran ceasefire have spurred a global market rally, with stock indices hitting record highs and risk sentiment improving. As tensions ease, oil prices stabilize, the dollar weakens, and investor focus shifts to corporate earnings and growth amid declining inflation concerns.

GateNews56m ago

Bank of England governor warns: Global stablecoin standards are lagging, calls for a unified regulatory framework

Bank of England Governor Andrew Bailey said at an IIF event that the effective functioning of stablecoins depends on users’ confidence in full redemption mechanisms, calling for the development of international standards. The United States has meanwhile released the GENIUS Act, requiring stablecoin issuers to meet compliance requirements. In South Korea, Circle’s CEO said there are no plans to launch a won-pegged stablecoin, and that the company is currently watching local legislative debates.

MarketWhisper1h ago

Sentinel Action Fund supports Jon Husted’s campaign for Ohio, investing $8 million

Sentinel Action Fund issued a statement on Wednesday, announcing that it will team up with its sister advocacy organization, Right Vote, to invest a total of $8 million in support of Ohio Republican Jon Husted’s campaign for U.S. senator. According to filings with the Federal Election Commission (FEC), the main donors include Solana Institute and Multicoin Capital.

MarketWhisper1h ago

Solana-Backed Super PAC Plans $8M to Support Jon Husted in Ohio Senate Race

The Sentinel Action Fund, supported by the Solana Foundation, will invest $8 million to aid Republican Senator Jon Husted in the Ohio Senate race against Sherrod Brown, who opposes crypto. Husted is known for advocating pro-crypto legislation.

GateNews2h ago

Australian Dollar Hits 36-Year High Against Yen as US-Iran Ceasefire Hopes Boost Risk Appetite

The Australian dollar has reached a 30-year high against the Japanese yen, propelled by optimism over a US-Iran ceasefire and a global equity rally. The RBA's hawkish policy and positive links to equity markets enhance AUD's appeal, though risks remain due to potential volatility.

GateNews4h ago

Gate Daily Report (April 16): Tether may have purchased 951 BTC; Virginia enacts crypto property law

Bitcoin continues to rise, reaching $74,630. Tether uses its profits to buy 951 bitcoins. Virginia passes an unclaimed property law, requiring idle cryptocurrency to be transferred to the state government. U.S. stocks are driven by tech stocks, and the S&P 500 index hits a new high. Crypto market dynamics show that investors are paying attention to geopolitical conditions and U.S. monetary policy.

MarketWhisper6h ago
Comment
0/400
No comments