• Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated on 06/17/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
ZK coprocessors let blockchains run heavy computation off-chain without sacrificing trust — here's how they work

ZK coprocessors let blockchains run heavy computation off-chain without sacrificing trust, here’s how they work

04/06/2026
North Korea’s six-month Solana infiltration proves social engineering is now crypto’s biggest threat

North Korea’s six-month Solana infiltration proves social engineering is now crypto’s biggest threat

04/06/2026
Bybit adds Rwandan franc to its P2P platform — the central bank responds within hours

Bybit adds Rwandan franc to its P2P platform, the central bank responds within hours

04/06/2026
  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated on 06/17/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
ZK coprocessors let blockchains run heavy computation off-chain without sacrificing trust — here's how they work

ZK coprocessors let blockchains run heavy computation off-chain without sacrificing trust, here’s how they work

04/06/2026
North Korea’s six-month Solana infiltration proves social engineering is now crypto’s biggest threat

North Korea’s six-month Solana infiltration proves social engineering is now crypto’s biggest threat

04/06/2026
Bybit adds Rwandan franc to its P2P platform — the central bank responds within hours

Bybit adds Rwandan franc to its P2P platform, the central bank responds within hours

04/06/2026
Monday, April 6, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

North Korean operatives spent six months infiltrating Drift before stealing $285 million

North Korean-linked actors exploited trust, tooling, and governance gaps to execute one of 2026’s largest DeFi breaches.

by Moses Edozie
3 hours ago
in Crypto News
Reading Time: 4 mins read
0
North Korean hackers
Share on FacebookShare on Twitter

A fake quantitative trading firm spent six months embedding itself inside Drift Protocol’s contributor network before draining approximately $285 million from the Solana-based perpetual futures exchange on April 1, 2026, the largest DeFi exploit of the year and an attack that combined sustained social engineering with malware deployment and on-chain manipulation to dismantle one of Solana’s most significant protocols in under a minute.

Ecosystem infiltration enabled Drift protocol attack

Between December 2025 and March 2026, the attackers deepened their foothold. As part of the Drift protocol attack, they onboarded an Ecosystem Vault, depositing over $1 million of their own funds. This move created operational legitimacy and reduced suspicion while integration discussions continued.

By the time the Drift protocol attack was executed, the relationship between attackers and contributors had matured over nearly half a year. This prolonged engagement allowed the attackers to understand internal processes, identify key personnel, and position themselves strategically within the ecosystem.

The Drift protocol attack highlights a critical vulnerability in DeFi: trust-based collaboration models that lack rigorous verification layers for participants.

Malware deployment triggered Drift protocol attack

The turning point in the Drift protocol attack came when attackers introduced malware through seemingly routine development workflows. One contributor reportedly cloned a repository provided by the fake trading firm, while another downloaded a wallet application via Apple’s TestFlight for testing.

These actions exploited a known vulnerability in widely used code editors such as VSCode and Cursor. Simply opening a compromised file could execute malicious code without warning. This enabled attackers to gain access to sensitive systems and credentials.

The Drift protocol attack did not rely on a single exploit but combined multiple vectors — social engineering, software vulnerabilities, and operational trust — to compromise key contributors.

Fake token manipulation fueled Drift protocol attack

While systems were being compromised, the attackers prepared the financial mechanism behind the Drift protocol attack. On March 11, 2026, they began staging on-chain activity using funds sourced from Tornado Cash.

They created a fraudulent asset, CarbonVote Token (CVT), and seeded it with minimal liquidity. Through wash trading and manipulation, the token appeared valuable enough to be accepted as collateral by Drift’s systems.

The Drift protocol attack exploited weaknesses in price oracles and governance controls. Despite prior audits, the introduction of the CVT market and recent governance changes created an opening that attackers leveraged.

Drift protocol attack executed in minutes

On April 1, 2026, the Drift protocol attack reached its climax. Using compromised access, attackers obtained multisig approvals required to execute transactions. These approvals had been pre-signed and remained dormant for over a week.

Once activated, the exploit drained funds from protocol vaults in under a minute. The rapid execution caused immediate disruption, with total value locked (TVL) dropping from about $550 million to under $300 million within an hour. The DRIFT token also fell sharply, losing over 40% of its value.

Drift protocol hack.
Drift protocol hack. A dozen Solana protocols were affected by the Drift protocol hack. Credit: SolanaFloor.

A dozen Solana protocols were affected by the Drift protocol hack. Credit: SolanaFloor.

In response, the team emphasized the seriousness of the situation. “Not an April Fool’s joke,” the protocol stated publicly, urging users to cease interactions immediately.

Laundering and attribution after Drift protocol attack

Following the breach, the Drift protocol attack entered its laundering phase. Stolen assets were quickly bridged to Ethereum, often in multimillion-dollar transactions. Funds were converted into USDC, SOL, and ETH, and moved through cross-chain protocols and centralized exchanges.

Blockchain analytics firms linked the Drift protocol attack to North Korean state-affiliated actors. Elliptic noted: “It is a continuation of the DPRK’s sustained campaign of large-scale cryptoasset theft, which the U.S. government has linked to the funding of its weapons programs,” — Elliptic.

The operation has been attributed with medium-high confidence to UNC4736, a group previously connected to major crypto breaches.

Industry response to Drift protocol attack

The aftermath of the Drift protocol attack rippled across the Solana ecosystem. Multiple protocols paused operations or assessed exposure. Some projects moved quickly to protect users by covering losses with internal funds, while others temporarily halted deposits and withdrawals.

Security experts have urged broader reflection. “You can’t grow if you’re hacked,” — @armaniferrante, security researcher, calling for comprehensive audits across custody, access control, and dependencies.

The Drift protocol attack has since prompted emergency measures, including freezing protocol functions, removing compromised wallets, and engaging cybersecurity firms for investigation.

Drift protocol attack underscores systemic risks

At $285 million, the Drift protocol attack is the largest DeFi exploit of 2026 and among the most significant in Solana’s history. More importantly, it underscores a shift in attack patterns.

The Drift protocol attack illustrates that the greatest vulnerabilities in decentralized systems may not lie in code alone, but in human trust, governance design, and operational security. As DeFi continues to grow, the incident serves as a stark reminder that technical robustness must be matched by equally strong social and procedural safeguards.

Tags: blockchain riskcrypto SecuritycybercrimedeFi hackDeFi SecurityDrift attackexploitsmalwarenorth koreaSolana breachtoken manipulationUNC4736
Share197Tweet123
Moses Edozie

Moses Edozie

Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.

  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated on 06/17/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
ZK coprocessors let blockchains run heavy computation off-chain without sacrificing trust — here's how they work

ZK coprocessors let blockchains run heavy computation off-chain without sacrificing trust, here’s how they work

04/06/2026
North Korea’s six-month Solana infiltration proves social engineering is now crypto’s biggest threat

North Korea’s six-month Solana infiltration proves social engineering is now crypto’s biggest threat

04/06/2026
Bybit adds Rwandan franc to its P2P platform — the central bank responds within hours

Bybit adds Rwandan franc to its P2P platform, the central bank responds within hours

04/06/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.