Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Today in Supreme Court History: May 2, 1927

26 minutes ago

Riot Posts $167M in Q1 Revenue as Data Center Arm Pulls in $33M

52 minutes ago

A Pointless War: How Iran Hawks Finally Got Their Way

1 hour ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Saturday, May 2
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»North Korean Hackers Spent Six Months Infiltrating Drift Before $285M Exploit
Cryptocurrency & Free Speech Finance

North Korean Hackers Spent Six Months Infiltrating Drift Before $285M Exploit

News RoomBy News Room4 weeks agoNo Comments3 Mins Read1,192 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
North Korean Hackers Spent Six Months Infiltrating Drift Before 5M Exploit
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Drift Protocol has attributed the recent $285 million attack on its DEX with “medium-high confidence” to UNC4736, a North Korean state-affiliated hacker group.
  • Attackers deposited over $1 million of their own capital and built a functioning vault inside the ecosystem before executing the exploit.
  • The bad actors erased traces instantly, with Telegram chats and malware “completely scrubbed” after execution.

Solana-based decentralized exchange Drift Protocol said on Sunday the attack that drained roughly $285 million from the platform was a structured six-month intelligence operation by a North Korean state-affiliated threat group.

The attackers used fabricated professional identities, in-person conference meetings, and malicious developer tools to compromise contributors before executing the drain, the protocol said in a detailed incident update.

“Crypto teams are now facing adversaries that operate more like intelligence units than hackers, and most organizations are not structurally prepared for that level of threat,” Michael Pearl, VP of Strategy at blockchain security firm Cyvers, told Decrypt.

Drift said the group first approached contributors at a major crypto conference last fall, presenting as a quantitative trading firm seeking to integrate with the protocol.

Over months, the group built trust through in-person meetings, Telegram coordination, onboarded an Ecosystem Vault on Drift, and made a $1 million vault deposit of their own capital, only to vanish, with chats and malware “completely scrubbed” when the exploit hit.

The DEX said the intrusion may have involved a malicious code repository, a fake TestFlight app, and a VSCode/Cursor vulnerability that enabled silent code execution without user interaction.

Drift attributed the attack with “medium-high confidence” to UNC4736, also tracked as AppleJeus or Citrine Sleet—the same North Korean state-affiliated group that cybersecurity firm Mandiant linked to 2024’s Radiant Capital hack.

Drift said the individuals who met contributors in person were not North Korean nationals, noting that DPRK-linked actors often rely on third-party intermediaries for “face-to-face engagement.”

Onchain fund flows and overlapping personas point to DPRK-linked actors, according to incident responders SEAL 911, though Mandiant has yet to confirm attribution pending forensics, the platform noted.

Security researcher @tayvano_, one of the experts whom Drift credited for assistance in identifying the malicious actors, suggested the exposure extend well beyond this incident.

In a tweet, the expert listed dozens of DeFi protocols, alleging that “DPRK IT workers built the protocols you know and love, all the way back to defi summer.”

Industry implications

“Drift and Bybit highlight the same pattern — signers were not directly compromised at the protocol level, they were tricked into approving malicious transactions,” Pearl noted. “The core issue is not the number of signers, but the lack of understanding of transaction intent.”

He said that multisignature wallets, while an improvement over single-key control, now create a false sense of security, introducing “a paradox” where shared responsibility lowers scrutiny across signers.

“Security must shift to pre-transaction validation at the blockchain level, where transactions are independently simulated and verified before execution,” Pearl said, adding that once attackers control what users see, the only effective defense is validating what a transaction actually does, regardless of the interface.

On developer tools as an attack surface, Lavid said the assumption has to change from the ground up.

“You have to assume the endpoint is compromised,” he told Decrypt, pointing to IDEs, code repositories, mobile apps, and signer environments as increasingly common entry points.

“If these foundational tools are vulnerable, anything shown to the user—including transactions—can be manipulated,” the expert said, noting this “fundamentally breaks traditional security assumptions,” leaving teams unable to trust “the interface, the device, or even the signing flow.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

Today in Supreme Court History: May 2, 1927

26 minutes ago
Cryptocurrency & Free Speech Finance

Riot Posts $167M in Q1 Revenue as Data Center Arm Pulls in $33M

52 minutes ago
Media & Culture

A Pointless War: How Iran Hawks Finally Got Their Way

1 hour ago
Media & Culture

California Lawmakers Are Ignoring History by Boosting Pension Benefits as the State’s Economy Teeters

2 hours ago
Cryptocurrency & Free Speech Finance

Ethereum Foundation Offloads $23M in ETH to BitMine for Third Time in Two Months

3 hours ago
Media & Culture

DHS Funded

3 hours ago
Add A Comment

Comments are closed.

Editors Picks

Riot Posts $167M in Q1 Revenue as Data Center Arm Pulls in $33M

52 minutes ago

A Pointless War: How Iran Hawks Finally Got Their Way

1 hour ago

California Lawmakers Are Ignoring History by Boosting Pension Benefits as the State’s Economy Teeters

2 hours ago

Ethereum Foundation Offloads $23M in ETH to BitMine for Third Time in Two Months

3 hours ago
Latest Posts

DHS Funded

3 hours ago

Is The Devil Wears Prada 2 the Great Millennial Journalism Movie?

5 hours ago

Bitcoin above $78K, ETH, SOL, DOGE higher as Senate clears Clarity Act yield hurdle

5 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Today in Supreme Court History: May 2, 1927

26 minutes ago

Riot Posts $167M in Q1 Revenue as Data Center Arm Pulls in $33M

52 minutes ago

A Pointless War: How Iran Hawks Finally Got Their Way

1 hour ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.