North Korean hackers infiltrated Drift Protocol over six months, posing as traders and meeting contributors in person, before executing a $285M exploit.
Security & Exploits ·
Drift Protocol attributed a $285 million attack on its Solana-based DEX to UNC4736, a North Korean state-affiliated hacker group, following what the protocol described as a structured six-month intelligence operation. The attackers used fabricated professional identities and in-person meetings at a major crypto conference last fall to approach contributors, presenting as a quantitative trading firm. Over the ensuing months, they built trust through continued in-person engagement, onboarded an Ecosystem Vault, and deposited $1 million of their own capital before executing the drain.
The infiltration reportedly involved malicious developer tools, a fake TestFlight app, and a code repository vulnerability that enabled silent execution. Drift attributed the breach with "medium-high confidence" to the same group linked to 2024's Radiant Capital hack. The attackers subsequently erased traces instantly, with Telegram chats and malware completely scrubbed after the exploit, and Drift noted the individuals who met contributors in person were not North Korean nationals, reflecting the group's typical reliance on third-party intermediaries.
Onchain fund flows and overlapping personas point to DPRK-linked actors according to incident responders SEAL 911, though Mandiant has not yet confirmed attribution pending forensics. The attack underscores a broader vulnerability in DeFi protocols, with security experts noting that multisignature wallets create a false sense of security when signers lack understanding of transaction intent.