Interesting story behind Drift Protocol Hack
-> On April 1, 2026, the Drift protocol (a DeFi platform on Solana) was exploited in a sophisticated attack that had been planned over six months.
-> Starting in Fall 2025, attackers posed as a legitimate quantitative trading firm, meeting Drift contributors in person at multiple crypto conferences across several countries. They built trust through months of genuine-looking engagement — discussing trading strategies, onboarding a vault, depositing over $1M of their own capital, and holding working sessions with team members.
-> The actual compromise likely happened through malicious software: one contributor cloned a code repository shared by the group, and another downloaded a TestFlight app they presented as a wallet product. A known VSCode/Cursor vulnerability from late 2025 may have been exploited, which allowed silent code execution just by opening a file.
-> Once the exploit occurred on April 1, the attackers scrubbed all their Telegram chats and malicious tools. Drift has since frozen protocol functions, removed compromised wallets from the multisig, and flagged attacker wallets across exchanges.
-> The attack is attributed with medium-high confidence to the same North Korean state-affiliated group (tracked as UNC4736/AppleJeus/Citrine Sleet) behind the October 2024 Radiant Capital hack, based on onchain fund flows and operational overlaps. Notably, the people who appeared in person were not North Korean nationals — DPRK groups are known to use third-party intermediaries for face-to-face interactions. Mandiant has been engaged but has not yet formally attributed the attack. The investigation is ongoing.
Source: https://x.com/DriftProtocol/status/2040611161121370409
Post #395
1.19K