TGViewer
Daily Security Daily Security @ethers_security · 4.02K subscribers
Post #395 1.19K
Interesting story behind Drift Protocol Hack

-> On April 1, 2026, the Drift protocol (a DeFi platform on Solana) was exploited in a sophisticated attack that had been planned over six months.

-> Starting in Fall 2025, attackers posed as a legitimate quantitative trading firm, meeting Drift contributors in person at multiple crypto conferences across several countries. They built trust through months of genuine-looking engagement — discussing trading strategies, onboarding a vault, depositing over $1M of their own capital, and holding working sessions with team members.

-> The actual compromise likely happened through malicious software: one contributor cloned a code repository shared by the group, and another downloaded a TestFlight app they presented as a wallet product. A known VSCode/Cursor vulnerability from late 2025 may have been exploited, which allowed silent code execution just by opening a file.

-> Once the exploit occurred on April 1, the attackers scrubbed all their Telegram chats and malicious tools. Drift has since frozen protocol functions, removed compromised wallets from the multisig, and flagged attacker wallets across exchanges.

-> The attack is attributed with medium-high confidence to the same North Korean state-affiliated group (tracked as UNC4736/AppleJeus/Citrine Sleet) behind the October 2024 Radiant Capital hack, based on onchain fund flows and operational overlaps. Notably, the people who appeared in person were not North Korean nationals — DPRK groups are known to use third-party intermediaries for face-to-face interactions. Mandiant has been engaged but has not yet formally attributed the attack. The investigation is ongoing.

Source: https://x.com/DriftProtocol/status/2040611161121370409
X (formerly Twitter) Velocity (@VelocityDEX) on X Drift Protocol — Incident Background Update
  • ❤ 1
More from @ethers_security
  1. Sep 24, 2026photo post
  2. Sep 24, 2026🚨🚨Bitget wallets may have been hacked after $174 million moves across chains 🚨🚨 [sourc…
  3. Aug 8, 2026Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages Recommendation: • If you id…
  4. Aug 1, 2026Great resource to study AI and different types of AI vulnerabilities https://riskatlas.pri…
  5. Jun 9, 2026Claude Fable is out. As you can see, the new model claims to have been significantly impro…
  6. Apr 23, 2026PASSWORD MANAGER 'BITWARDEN' CLI WAS COMPROMISED IN A SUPPLY CHAIN ATTACK ⚠️ BITWARDEN CLI…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →