North Korean hackers infiltrated Drift Protocol over six months by posing as traders and meeting contributors in person, then executed a $285M exploit.
Security & Exploits ·
Drift Protocol attributed a $285 million attack on its Solana-based platform to UNC4736, a North Korean state-affiliated hacker group, with "medium-high confidence." The attackers executed what the protocol described as a structured six-month intelligence operation, using fabricated professional identities and in-person meetings at crypto conferences to approach and build relationships with contributors before gaining access to the system.
The infiltration involved multiple technical and social engineering vectors. The group first presented itself as a quantitative trading firm seeking integration, then deposited over $1 million of its own capital into an Ecosystem Vault while coordinating through Telegram. Drift said the intrusion may have leveraged a malicious code repository, a fake TestFlight app, and a vulnerability in VSCode or Cursor that allowed code execution without user interaction. Upon executing the exploit, attackers immediately removed traces, with Telegram chats and malware completely scrubbed from the platform.
Attribution remains incomplete despite the medium-high confidence assessment. Onchain fund flows and overlapping personas pointed to DPRK-linked actors according to incident responders SEAL 911, yet cybersecurity firm Mandiant has not yet confirmed the attribution pending forensics, as Drift noted. The protocol also observed that individuals meeting contributors in person were not North Korean nationals, consistent with reported reliance on third-party intermediaries for face-to-face engagement.