{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:19:17.233Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Six-month DPRK social engineering operation preceded $285M Drift Protocol theft","date":"2026-04-01","date_precision":"day","victim_org":"Drift Protocol","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Physical Pretexting","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.","outcomes":["Cryptocurrency Theft"],"loss_usd":285000000,"loss_note":"USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.","records_affected":null,"threat_actor":"UNC4736 / AppleJeus / Citrine Sleet / Golden Chollima / Gleaming Pisces (DPRK), medium confidence","summary":"Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.","how_it_worked":"This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.","lessons":"Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.","confidence":"Reported","sources":[{"title":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html","publisher":"The Hacker News"},{"title":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks","publisher":"TRM Labs"}],"entry_type":"incident","slug":"2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol","year":2026,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-six-month-dprk-social-engineering-operation-preceded-285m-drift-protocol"}]}