• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: North Korean Group Behind $270 Million Drift Protocol Exploit After Months of Deception
Share
  • bitcoinBitcoin(BTC)$67,315.00
  • ethereumEthereum(ETH)$2,054.57
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$592.29
  • rippleXRP(XRP)$1.30
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$79.64
  • tronTRON(TRX)$0.319133
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • dogecoinDogecoin(DOGE)$0.090715
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

North Korean Group Behind $270 Million Drift Protocol Exploit After Months of Deception

News Desk
Last updated: April 5, 2026 4:16 pm
News Desk
Published: April 5, 2026
Share
ae3d310326c0f8a1991358d50350b2eaff5fae4e 1724x900

A recent intelligence update reveals that a sophisticated $270 million exploit of the Drift Protocol was executed by a North Korean state-affiliated group, following a complex six-month intelligence operation. The attack was meticulously planned, beginning with the group’s initial contact at a significant crypto conference in the fall of 2025, where they posed as a quantitative trading firm interested in integrating with Drift.

The attackers displayed considerable technical expertise, showcasing verifiable professional backgrounds while engaging in lengthy discussions about trading strategies and vault integrations—conversations typical of legitimate trading firm engagements with decentralized finance (DeFi) protocols. As the relationship developed, a Telegram group was set up for ongoing communications. Between December 2025 and January 2026, the group successfully onboarded an Ecosystem Vault within Drift, participated in several working sessions with contributors, and even invested over $1 million of their own capital, establishing a credible operational presence within the ecosystem.

The subterfuge allowed the attackers to build substantial rapport, meeting Drift contributors face-to-face at various high-profile industry conferences throughout February and March. This groundwork laid a convincing foundation that facilitated their ultimate attack on April 1, nearly six months after they had first made contact.

The compromise occurred via two primary vectors. The first involved the group’s use of a TestFlight application, which is Apple’s mechanism for distributing pre-release software and bypassing standard App Store security protocols. They presented this application as their wallet product. The second vector exploited a known vulnerability in widely-used code editors—VSCode and Cursor—allowing the execution of arbitrary code simply by opening a file or folder. This vulnerability had been flagged by the security community since late 2025.

Once the attackers compromised the relevant devices, they gained unauthorized access to secure multisig approvals necessary for executing a durable nonce attack. These pre-signed transactions, which remained dormant for over a week, were executed on April 1, resulting in the rapid draining of $270 million from Drift’s vaults in less than a minute.

Attribution for the attack points to UNC4736, a North Korean state-affiliated group also known as AppleJeus or Citrine Sleet. This assessment is supported by on-chain fund flow patterns linking the exploit back to previous attacks associated with Radiant Capital, along with operational similarities to other known DPRK-linked individuals. Interestingly, the perpetrators who interacted with Drift at the conferences were not nationals of North Korea; they are believed to be high-level DPRK operatives using third-party intermediaries with well-crafted identities and professional histories designed to withstand scrutiny.

In the aftermath, Drift has called upon other protocols to reassess their access controls, emphasizing that any device interacting with a multisig setup constitutes a potential vulnerability. This alarming incident raises significant concerns regarding the security framework relied upon by the DeFi ecosystem, particularly given that attackers are now willing to invest considerable time and resources—six months and a million dollars—to craft a façade of legitimacy, fostering relationships and penetrating systems before executing large-scale fraud. The central question now lingers: what security model can deter such sophisticated and multifaceted threats in the future?

U.S. Bitcoin ETFs Face Record Outflows Amid Price Stability Around $100,000
Best Crypto Presales of 2025: BlockchainFX and Chainlink Poised for Growth
Two Brothers Arrested for Home Invasion and Kidnapping Near Mahtomedi High School
US Dollar Declines as Investors Assess NFP Figures and Fed Rate Cut Expectations
Ethereum Price Holds Above $4,500 as Institutional Demand Boosts Bullish Momentum
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 1775405160 og Polymarket Traders Set Odds on Bitcoin Price Movements in Real Time
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
1775405160 og
Polymarket Traders Set Odds on Bitcoin Price Movements in Real Time
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8638192F180bc861f15babdaf4161529811b35c72e4
Market Misread on Google TurboQuant Creates Opportunity for Marvell Technology
1775404382 og
Polymarket Traders Assess Real-Time Bitcoin Price Momentum
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?