The post North Korea-Linked Group Behind $270M Drift Hack, Six-Month Plot Revealed appeared on BitcoinEthereumNews.com. What initially appeared to be a sudden exploitThe post North Korea-Linked Group Behind $270M Drift Hack, Six-Month Plot Revealed appeared on BitcoinEthereumNews.com. What initially appeared to be a sudden exploit

North Korea-Linked Group Behind $270M Drift Hack, Six-Month Plot Revealed

For feedback or concerns regarding this content, please contact us at [email protected]

What initially appeared to be a sudden exploit has now been revealed as a long-term, highly coordinated operation. Drift Protocol has disclosed that the $270 million hack was the result of a six-month infiltration campaign, allegedly tied to North Korean state-linked actors.

Rather than exploiting a simple vulnerability, the attackers built trust slowly, posing as a legitimate quantitative trading firm and embedding themselves within the ecosystem. Their approach went beyond digital deception. They engaged contributors directly, attended crypto conferences, and established relationships that appeared credible at every level.

This was not a smash-and-grab attack. It was calculated, patient, and designed to bypass not just technical defenses but human trust.

First Contact Begins At Crypto Conferences

The operation reportedly began in fall 2025, when the attackers made first contact at a major crypto conference. At the time, there were no immediate red flags. The group presented themselves as technically proficient professionals with verifiable backgrounds.

They spoke the language of DeFi fluently, demonstrating a deep understanding of Drift’s infrastructure and trading mechanisms. This level of expertise helped them blend in seamlessly with legitimate contributors and partners.

Soon after, communication moved to Telegram, where discussions continued over several months. These interactions were not rushed or suspicious. Instead, they mirrored the cadence of real collaboration, complete with technical discussions, strategic input, and ongoing engagement.

By maintaining consistency and credibility, the attackers gradually built trust within the community.

Building Trust Through Capital And Collaboration

By January 2026, the group had taken their involvement even further. They successfully onboarded an Ecosystem Vault and began participating in working sessions alongside Drift contributors.

Crucially, they also committed real capital, depositing over $1 million of their own funds into the protocol. This move reinforced their legitimacy, signaling that they had skin in the game.

Throughout February and March, members of the Drift ecosystem met these individuals in person across multiple countries. These face-to-face interactions added another layer of trust, making it even less likely that their intentions would be questioned.

By the time the attack was executed, the relationship between the attackers and the community had been established for nearly six months. It was a level of infiltration rarely seen in DeFi exploits.

Attack Execution Leveraged Sophisticated Entry Points

When the compromise finally occurred, it came through two highly targeted vectors.

The first involved a malicious TestFlight application, presented as a legitimate wallet product. This allowed the attackers to gain access to contributor devices under the guise of testing new tools.

The second vector exploited a known vulnerability in development environments like VSCode and Cursor. This flaw, flagged by the security community months earlier, enabled the execution of arbitrary code simply by opening a file.

Together, these methods allowed the attackers to compromise key devices without triggering immediate suspicion. Once inside, they were able to access sensitive workflows and approval mechanisms.

This stage of the operation highlights a critical shift in attack strategies. Instead of targeting smart contracts directly, attackers are increasingly focusing on the human and tooling layers surrounding them.

Multisig Weaknesses Exposed In Final Drain

With access secured, the attackers moved to the final phase: execution.

They obtained two multisig approvals, which were then used to authorize transactions. Notably, these transactions were pre-signed and left dormant for over a week, avoiding immediate detection.

On April 1, the attackers acted. In under a minute, approximately $270 million was drained from Drift’s vaults.

The speed and precision of the execution left little room for intervention. By the time the transactions were recognized, the funds had already been moved.

Drift has since warned that this incident exposes fundamental weaknesses in multisig-based security models. While multisig systems are designed to distribute trust, they remain vulnerable when signers themselves are compromised.

Links To North Korean State Actors Surface

Investigations into the attack have linked the operation to UNC4736, a group also known as AppleJeus or Citrine Sleet. This entity is widely associated with North Korean cyber operations and has been connected to previous high-profile exploits, including the Radiant Capital attack.

Interestingly, the individuals who interacted directly with Drift contributors were not identified as North Korean nationals. Instead, they appear to have been third-party intermediaries, equipped with carefully constructed identities designed to withstand scrutiny.

This layered approach makes attribution more complex while increasing the effectiveness of the operation. By separating the on-the-ground actors from the coordinating entity, the attackers were able to maintain plausible legitimacy throughout the infiltration.

A Wake-Up Call For DeFi Security Models

The Drift exploit is forcing the industry to confront an uncomfortable reality. Traditional security models, focused on code audits, smart contract vulnerabilities, and multisig protections, may not be enough to defend against adversaries willing to invest time, money, and human resources.

If attackers can spend six months building relationships, deploy capital to gain trust, and physically meet with teams, the attack surface extends far beyond code.

This raises a critical question for the DeFi ecosystem: what kind of security framework can detect and prevent this level of infiltration?

For now, the incident stands as one of the most sophisticated social-engineering-driven exploits in crypto history. It underscores the need for a more holistic approach to security, one that accounts for human behavior, operational processes, and the increasingly blurred lines between online and offline interactions.

As protocols continue to grow and attract more capital, the stakes will only rise. And as this case shows, the next generation of attacks may not come from anonymous wallets, but from trusted partners sitting across the table.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Source: https://nulltx.com/north-korea-linked-group-behind-270m-drift-hack-six-month-plot-revealed/

Market Opportunity
Drift Protocol Logo
Drift Protocol Price(DRIFT)
$0.01837
$0.01837$0.01837
-2.75%
USD
Drift Protocol (DRIFT) Live Price Chart

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

NEAR Protocol Price Surges 10% as Bullish Technical Setup Puts $3.50 in Sight

NEAR Protocol Price Surges 10% as Bullish Technical Setup Puts $3.50 in Sight

The post NEAR Protocol Price Surges 10% as Bullish Technical Setup Puts $3.50 in Sight appeared first on Coinpedia Fintech News The AI crypto narrative is gaining
Share
CoinPedia2026/06/03 17:23
CME Group to launch Solana and XRP futures options in October

CME Group to launch Solana and XRP futures options in October

The post CME Group to launch Solana and XRP futures options in October appeared on BitcoinEthereumNews.com. CME Group is preparing to launch options on SOL and XRP futures next month, giving traders new ways to manage exposure to the two assets.  The contracts are set to go live on October 13, pending regulatory approval, and will come in both standard and micro sizes with expiries offered daily, monthly and quarterly. The new listings mark a major step for CME, which first brought bitcoin futures to market in 2017 and added ether contracts in 2021. Solana and XRP futures have quickly gained traction since their debut earlier this year. CME says more than 540,000 Solana contracts (worth about $22.3 billion), and 370,000 XRP contracts (worth $16.2 billion), have already been traded. Both products hit record trading activity and open interest in August. Market makers including Cumberland and FalconX plan to support the new contracts, arguing that institutional investors want hedging tools beyond bitcoin and ether. CME’s move also highlights the growing demand for regulated ways to access a broader set of digital assets. The launch, which still needs the green light from regulators, follows the end of XRP’s years-long legal fight with the US Securities and Exchange Commission. A federal court ruling in 2023 found that institutional sales of XRP violated securities laws, but programmatic exchange sales did not. The case officially closed in August 2025 after Ripple agreed to pay a $125 million fine, removing one of the biggest uncertainties hanging over the token. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/cme-group-solana-xrp-futures
Share
BitcoinEthereumNews2025/09/17 23:55
Best Crypto Presale 2026: $GRUNTLE Crosses $105k as ETH and DOGE Drop 9%

Best Crypto Presale 2026: $GRUNTLE Crosses $105k as ETH and DOGE Drop 9%

The post Best Crypto Presale 2026: $GRUNTLE Crosses $105k as ETH and DOGE Drop 9% appeared first on Coinpedia Fintech News Bullish crypto positions lost $1.6 billion
Share
CoinPedia2026/06/03 17:22

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage