Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationUnknownReported

Six-month DPRK social engineering operation preceded $285M Drift Protocol theft

Drift Protocol · Cryptocurrency · Unknown · April 1, 2026

Funds lost
$285,000,000
Money actually taken from, or wired out by, the victim.
USD 285 million per TRM Labs and reporting on the April 1, 2026 theft. TRM assessed North Korea took 76 percent of all 2026 crypto hack value across just two attacks, of which this was one.

What happened

Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.

How the deception worked

This was a six-month cultivation, not a lure. The operators met Drift contributors face to face at conferences, which removed the usual doubts about an unsolicited online approach, then sustained real technical discussion about vault integrations over Telegram for months. They spent more than $1 million of their own funds onboarding an Ecosystem Vault, buying the standing of a paying counterparty. With that relationship in place, two suspected vectors compromised contributors: a malicious code repository shared in the course of integration work, and a weaponised wallet application distributed through Apple's TestFlight beta programme. TRM Labs reported the attackers also exploited Solana durable nonces to have authorised signers pre-authorise transactions weeks before execution, alongside three weeks of on-chain staging from March 11.

AI involvement · Unknown

No AI-generated media was specified in the reporting reviewed; the operation relied on in-person meetings and sustained relationship building.

The control that would have caught it· our reading, not a claim from the sources

Counterparty relationship length and capital deposited are not identity evidence; code and applications from any external partner must run only in isolated environments, and durable-nonce or other pre-authorised transactions need expiry and re-verification before they can settle.

Sources (2)

  1. $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
    The Hacker News·thehackernews.comOpen ↗
  2. North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks
    TRM Labs·trmlabs.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.