Drift Protocol’s $285 Million Heist Started With a Handshake and 6 Months of Trust

Source Beincrypto

Drift Protocol (DRIFT) published a detailed incident update on April 5, revealing that the $285 million exploit on April 1 was the result of a six-month intelligence operation attributed to North Korean state-backed actors.

The disclosure describes a level of social engineering that goes well beyond typical phishing or recruiter scams, involving in-person meetings, real capital deployment, and months of trust-building.

A Fake Trading Firm That Played the Long Game

According to Drift, a group posing as a quantitative trading firm first approached contributors at a major crypto conference in fall 2025.

Over the following months, these individuals appeared at multiple events across several countries, held working sessions, and maintained ongoing Telegram conversations about vault integrations.

Follow us on X to get the latest news as it happens

Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, deposited over $1 million in capital, and participated in detailed product discussions.

By March, Drift contributors had met these individuals face-to-face on multiple occasions.

“…the most dangerous hackers don’t look like hackers,” commented crypto developer Gautham.

Even Web security experts find this concerning, with researcher Tay sharing that she initially expected a typical recruiter scam but found the operation’s depth far more alarming.

How the Devices Were Compromised

Drift identified three likely attack vectors:

  • One contributor cloned a code repository the group shared for a vault frontend.
  • A second downloaded a TestFlight application presented as a wallet product.
  • For the repository vector, Drift pointed to a known VSCode and Cursor vulnerability that security researchers had been flagging since late 2025.

That flaw allowed arbitrary code to execute silently the moment a file or folder was opened in the editor, with no user interaction required.

After the April 1 drain, the attackers scrubbed all Telegram chats and malicious software. Drift has since frozen remaining protocol functions and removed compromised wallets from the multisig.

The SEALS 911 team assessed with medium-high confidence that the same threat actors carried out the October 2024 Radiant Capital hack, which Mandiant attributed to UNC4736.

On-chain fund flows and operational overlaps between the two campaigns support that connection.

Industry Calls for a Security Reset

Armani Ferrante, a prominent Solana developer, called on every crypto team to pause growth efforts and audit their entire security stack.

“Every team in crypto should use this as an opportunity to slow down and focus on security. If possible, dedicate an entire team to it… you can’t grow if you’re hacked,” said Ferrante.

Drift noted that the individuals who appeared in person were not North Korean nationals. DPRK threat actors at this level are known to deploy third-party intermediaries for face-to-face engagement.

Mandiant, which Drift has engaged for device forensics, has not yet formally attributed the exploit.

The disclosure serves as a warning to the broader ecosystem. Drift urged teams to audit access controls, treat every device that touches a multisig as a potential target, and contact SEAL 911 if they suspect similar targeting.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Eightco holds $326M in treasury, heavily weighted toward AI via its exposure to Worldcoin and OpenAI.Nasdaq-listed Eightco, also known as ORBS, has reported its total crypto holdings to start April, worth $326 million, with Worldcoin and artificial intelligence (AI) investments accounting for the lion’s share of its holdings.  ZeroStack, another Nasdaq-listed company, shared that it has made an institutional commitment of $107 million as it plans to increase its strategic […]
Author  Cryptopolitan
Apr 03, Fri
Nasdaq-listed Eightco, also known as ORBS, has reported its total crypto holdings to start April, worth $326 million, with Worldcoin and artificial intelligence (AI) investments accounting for the lion’s share of its holdings.  ZeroStack, another Nasdaq-listed company, shared that it has made an institutional commitment of $107 million as it plans to increase its strategic […]
placeholder
Iran sets $1 a barrel Hormuz oil passage toll payable in yuan or stablecoinsIran is putting a price on passage through the Strait of Hormuz, with a new toll system that starts oil tankers at about $1 per barrel and asks for payment in yuan or stablecoins. The first step came when Iran’s National Security Committee approved a bill to charge ships using the route, Fars reported, citing […]
Author  Cryptopolitan
Apr 03, Fri
Iran is putting a price on passage through the Strait of Hormuz, with a new toll system that starts oil tankers at about $1 per barrel and asks for payment in yuan or stablecoins. The first step came when Iran’s National Security Committee approved a bill to charge ships using the route, Fars reported, citing […]
placeholder
Circle bets on cirBTC to unlock Bitcoin yield as DeFi demand growsCircle is placing its bets on cirBTC to tap into Bitcoin earnings as the demand for DeFi increases. 
Author  Cryptopolitan
Apr 03, Fri
Circle is placing its bets on cirBTC to tap into Bitcoin earnings as the demand for DeFi increases. 
placeholder
Chainlink Whale Activity Rises While Price Bleeds for 7 Straight MonthsChainlink (LINK) is seeing an increase in whale activity, according to CryptoQuant analyst Darkfost. In a recent analysis, he flagged two notable daily peaks where the top 10 whale outflow transaction
Author  Beincrypto
Apr 03, Fri
Chainlink (LINK) is seeing an increase in whale activity, according to CryptoQuant analyst Darkfost. In a recent analysis, he flagged two notable daily peaks where the top 10 whale outflow transaction
placeholder
NVIDIA Stock Rallied 8%, But 3 Signals Point to a ReversalNVIDIA (NVDA) stock price surged roughly 8% between March 30 and April 1, reclaiming $175.75 after weeks of selling pressure.The rally had clear catalysts. However, underneath the optimism, institutio
Author  Beincrypto
Apr 03, Fri
NVIDIA (NVDA) stock price surged roughly 8% between March 30 and April 1, reclaiming $175.75 after weeks of selling pressure.The rally had clear catalysts. However, underneath the optimism, institutio
goTop
quote