Drift Protocol investigation reveals $285M theft was a six-month coordinated operation by attackers posing as quants, potentially linked to North Korean hacking group behind 2024 Radiant Capital exploit.
Security & Exploits ·
Drift Protocol has concluded its investigation into a $285 million theft, determining that the attack was a coordinated operation spanning roughly six months. Beginning in fall 2025, attackers impersonated a quantitative trading firm and repeatedly engaged Drift team members at international crypto conferences, ultimately compromising devices via code repository links and the TestFlight application.
The investigation suggests a connection to the North Korean-linked hacking group responsible for the 2024 Radiant Capital exploit, though the exact nature and strength of that link remain unclear. The long duration and multi-vector approach—combining social engineering at industry events with technical entry points—indicate a sophisticated, patient infiltration rather than a sudden breach.
What remains unknown is whether law enforcement or blockchain security firms have independently corroborated the North Korean link, what specific vulnerabilities were exploited once devices were compromised, and whether any of the stolen funds have been traced or recovered on-chain.