Drift Protocol was targeted by a 6-month sophisticated social engineering campaign attributed to North Korean state actors who posed as a quant firm, built relationships, and infiltrated via shared repositories and a fake TestFlight wallet.
Security & Exploits ·
Drift Protocol disclosed a sophisticated social engineering attack spanning six months, attributed to North Korean state actors who posed as a quantitative trading firm at multiple conferences. The attackers built relationships with protocol insiders, onboarded a vault containing $1M or more of assets, and gained access through shared code repositories and a counterfeit TestFlight wallet application.
The attack relied on sustained impersonation and trust-building rather than immediate technical exploitation. By positioning themselves as legitimate market participants across industry events, the actors cultivated connections that enabled them to request repository access and distribute a fraudulent mobile wallet, creating multiple vectors for infiltration and potential asset compromise.
The disclosure does not clarify whether funds were lost, the exact entry point that led to detection, or what countermeasures Drift has since deployed. It remains unclear how many team members or how much internal infrastructure was compromised beyond the identified vault and code access points.