Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

BTC enters April at its most hated level since the war began

42 minutes ago

AI is breaking crypto security by making hacks cheaper and easier, Ledger CTO warns

2 hours ago

Bitcoin Prepping New Lows, Trader Warns as Bollinger Bands Tighten

2 hours ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Sunday, April 5
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Drift says $270 million exploit was a six-month North Korean intelligence operation
Cryptocurrency & Free Speech Finance

Drift says $270 million exploit was a six-month North Korean intelligence operation

News RoomBy News Room4 hours agoNo Comments3 Mins Read1,356 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Drift says 0 million exploit was a six-month North Korean intelligence operation
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

A six-month intelligence operation preceded the $270 million exploit of Drift Protocol and was carried out by a North Korean state-affiliated group, according to a detailed incident update published by the team earlier on Sunday.

The attackers first made contact around fall 2025 at a major crypto conference, presenting themselves as a quantitative trading firm looking to integrate with Drift.

They were technically fluent, had verifiable professional backgrounds, and understood how the protocol operated, Drift said. A Telegram group was established and what followed were months of substantive conversations around trading strategies and vault integrations, interactions that are standard for how trading firms onboard with DeFi protocols.

Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, held multiple working sessions with contributors, deposited over $1 million of their own capital, and built a functioning operational presence inside the ecosystem.

Drift contributors met individuals from the group face to face at multiple major industry conferences across several countries through February and March. By the time the attack launched on April 1, the relationship was nearly half a year old.

The compromise appears to have come through two vectors.

A second downloaded a TestFlight application, Apple’s platform for distributing pre-release apps that bypasses App Store security review, which the group presented as their wallet product.

For the repository vector, Drift pointed to a known vulnerability in VSCode and Cursor, two of the most widely used code editors in software development, that the security community had been flagging since late 2025, where simply opening a file or folder in the editor was sufficient to silently execute arbitrary code with no prompt or warning of any kind.

Once devices were compromised, the attackers had what they needed to obtain the two multisig approvals that enabled the durable nonce attack CoinDesk detailed earlier this week. Those pre-signed transactions sat dormant for more than a week before being executed on April 1, draining $270 million from the protocol’s vaults in under a minute.

The attribution points to UNC4736, a North Korean state-affiliated group also tracked as AppleJeus or Citrine Sleet, based on both on-chain fund flows tracing back to the Radiant Capital attackers and operational overlap with known DPRK-linked personas.

The individuals who appeared in person at conferences were not North Korean nationals, however. DPRK threat actors at this level are known to deploy third-party intermediaries with fully constructed identities, employment histories, and professional networks built to withstand due diligence.

Drift urged other protocols to audit access controls and treat every device touching a multisig as a potential target. The broader implication is uncomfortable for an industry that relies on multisig governance as its primary security model.

But if attackers are willing to spend six months and a million dollars building a legitimate presence inside an ecosystem, meet teams in person, contribute real capital, and wait, the question is what security model is designed to catch that.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

BTC enters April at its most hated level since the war began

42 minutes ago
Cryptocurrency & Free Speech Finance

AI is breaking crypto security by making hacks cheaper and easier, Ledger CTO warns

2 hours ago
Cryptocurrency & Free Speech Finance

Bitcoin Prepping New Lows, Trader Warns as Bollinger Bands Tighten

2 hours ago
Cryptocurrency & Free Speech Finance

Ant Group’s blockchain arm unveils platform for AI agents to transact on crypto rails

3 hours ago
Cryptocurrency & Free Speech Finance

Kiyosaki Says 1974 Shift Drives Debt Crisis, Backs Bitcoin and gold

3 hours ago
Cryptocurrency & Free Speech Finance

Crypto Token Glut Is Diluting Value And Breaking Investor Returns

5 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

AI is breaking crypto security by making hacks cheaper and easier, Ledger CTO warns

2 hours ago

Bitcoin Prepping New Lows, Trader Warns as Bollinger Bands Tighten

2 hours ago

Ant Group’s blockchain arm unveils platform for AI agents to transact on crypto rails

3 hours ago

Kiyosaki Says 1974 Shift Drives Debt Crisis, Backs Bitcoin and gold

3 hours ago
Latest Posts

Drift says $270 million exploit was a six-month North Korean intelligence operation

4 hours ago

Today in Supreme Court History: April 5, 1982

4 hours ago

Crypto Token Glut Is Diluting Value And Breaking Investor Returns

5 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

BTC enters April at its most hated level since the war began

42 minutes ago

AI is breaking crypto security by making hacks cheaper and easier, Ledger CTO warns

2 hours ago

Bitcoin Prepping New Lows, Trader Warns as Bollinger Bands Tighten

2 hours ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.