Drift details how suspected North Korean attackers stole $270M posing as a quant trading firm in a 6+ month operation with in-person meetings and a $1M+ deposit
Attackers posed as a trading firm, met Drift contributors in person across multiple countries, deposited $1 million of their own capital …
CoinDeskShaurya Malwa
Context & Ripple Effects
Drift’s earlier warning of an active protocol attack initially framed the incident as an on-chain security event. The subsequent account instead makes counterparty impersonation and extended trust-building central to how the loss occurred.
The case sits within a broader run of reported North Korea-linked crypto thefts: coverage later grouped Drift and KelpDAO at roughly $577M in April in combined reported losses. That connects a single protocol breach to the sector’s persistent state-linked crypto-heist problem.
First-order effects
Drift and its contributors must treat prospective trading firms and other high-trust counterparties as a security-control issue, not solely a commercial or liquidity relationship.
Users and liquidity providers face immediate confidence damage after a large loss tied to a months-long social-engineering operation rather than a plainly detectable external attack.
Second-order effects
Other DeFi protocols and market makers are pressured to tighten counterparty verification, access approvals, and monitoring for partners whose capital deposits or personal meetings previously signaled legitimacy.
The incident raises the operating cost of institutional-looking participation in DeFi: legitimate quant firms may face more diligence, while protocols may become less willing to grant privileged integrations or bespoke access.
Third-order effects
If sophisticated identity-based infiltration continues, DeFi security will increasingly be defined by governance and counterparty controls alongside smart-contract auditing—a core aspect of the crypto legitimacy gap.
Repeated state-linked losses could deepen the divide between protocols able to demonstrate credible operational controls and those relying primarily on permissionless access and informal trust; the extent of that divide depends on whether outflows persist after major incidents.
The trend: This is one data point in the shift from isolated smart-contract exploits toward blended, long-horizon social and operational attacks on crypto infrastructure.
The preliminary investigation shows that Drift experienced a structured intelligence operation [...] Drift contributors were approached by a group of individuals at a major crypto conference who presented as a quantitative trading firm looking to integrate on the protocol. [...]…
The more I sit on this, the more I can't help but think we're dealing with a civil negligence issue. Sorry for how long this rant will be in advance, but I'm just so angry. Drift Protocol was handling hundreds of millions in user money. They knew crypto is full of hackers -
ANALYSIS 🧵: The $270M Drift Protocol hack was a six-month North Korean intelligence operation. Attackers posed as a quant trading firm, met contributors in person at conferences across multiple countries, and deposited $1M of their own capital before executing the drain.
The compromise came through two vectors: → A malicious TestFlight app presented as their wallet product → A known VSCode/Cursor vulnerability where opening a file silently executes arbitrary code — flagged by the security community since late 2025
I'll probably get attacked for saying this, but every team in crypto should use this as an opportunity to slow down and focus on security. If possible, dedicate an entire team to it. I know how hard it is. There's an enormous amount of pressure to grow at all costs. Your
Once devices were compromised, attackers obtained two multisig approvals. Those pre-signed transactions sat dormant for more than a week. On April 1, they drained $270M from Drift's vaults in under a minute.
Diving deep on Drift's exploit w/ @laurashin on @Unchained_pod. This exploit was methodical and calculated. The exploiters spent time studying Drift deeply. The game of security/risk is asymmetric: You only need to be wrong once for it to be over.
This story is insane. North Korea stole $285 million from a crypto protocol in 12 minutes. But the operation started 6 months ago with real life spies. It reads like a thriller: A group posing as a quant trading firm approached Drift Protocol contributors at a crypto conference […
Don't trust anyone Don't install apps Have dedicated devices for signing The game has changed Review your security practices and verify they fulfill your needs
THIS IS INSANE.🤯 North Korea stole $285 million in 12 minutes. Drift is the biggest trading platform on Solana. The code was fine. Two audits found nothing wrong. North Korea didn't touch the code. They went after the people. They made a fake token called CarbonVote. Put in [imag…
The uncomfortable question the Drift exploit is now asking the industry: If attackers are willing to spend six months and $1M building a legitimate presence, meet your team in person, and wait — what security model catches that? Drift warns the attack exposes deep weaknesses in
So, let me get this straight. The $280m Drift hack took six months of: - Attending crypto conferences. - Meeting the team in person. Multiple times. - Depositing $1M of their own capital to build trust. - Sharing a GitHub link. The biggest DeFi exploit of the year started at a
north korea deposited $1M into drift, attended conferences for 6 months, and built real relationships with the team. the most dangerous hackers don't look like hackers.
pretty crazy if true tl:dr - hackers casually gained trust via irl conference meet, setup tg channel and became a customer, started building integrations over 6 months and then got one person with a testflight link to show off what they built
The underlying lessons here: Keep your wallets away from your work laptop and phone Dedicated device for signing, maybe running on a cellular connection Trust nobody
I beg everyone in crypto to read this in full. I expected this to be another case of social engineering, likely some recruiter/job offer shit. I was very wrong. And the depth of the operation and personas makes me think they already have multiple other teams on lock. 😳
Another week, another DeFi exploit 🫠 @omeragoldberg joined me to unpack the Drift Protocol hack: ⁉️ What went wrong? 👀 How the attack resembles the Mango DAO and Resolv exploits 🤔 Why was Circle so slow to react? ⚠️Are North Korean state actors behind the attack? [video]