Elliptic attributes $286M Drift Protocol exploit to North Korean hackers, revealing identical multisig breach pattern to Bybit.
Security & Exploits ·
Blockchain analytics firm Elliptic flagged the $285 million Drift Protocol exploit as likely the work of North Korean state-sponsored hackers, citing multiple onchain indicators including premeditated transaction staging, structured laundering flows across chains, and patterns matching prior DPRK-linked operations. If confirmed, this would mark the eighteenth North Korean attack Elliptic has tracked in the current period, with cumulative theft exceeding $300 million. The U.S. government has linked such thefts to funding North Korea's weapons programs.
The exploit of Drift Protocol, a Solana-based perpetual futures exchange, was compounded by technical factors that hampered investigation. Solana's account model fragments activity tied to a single attacker across multiple addresses, obscuring the full picture unless investigators use entity-level clustering to link token accounts. Funds moved rapidly from Solana to Ethereum and other chains following the breach, reflecting a structured, repeatable laundering methodology designed to obscure origin while retaining control.
Key uncertainties remain unresolved: whether North Korean attribution will be definitively confirmed, the complete scope of funds still in motion, and how effectively cross-chain forensics can track assets as laundering tactics evolve. Drift Protocol's token has declined over 40% since the incident.