Crypto20 April, 20261 min read
North Korean Intel Runs Six-Month Con to Hack $270 Million from Drift
North Korea-linked actors conducted a six-month intelligence operation against Drift. Attackers posed as a trading firm, met Drift contributors abroad, deposited $1M, waited six months.

Elaborate Infiltration
Drift Protocol was hacked for $270 million in a six-month North Korean intelligence operation. Attackers posed as a quantitative trading firm, meeting contributors in person across multiple countries.
They deposited over $1 million of their own capital and integrated an Ecosystem Vault. The exploit did not stem from a smart contract bug but from compromised administrative controls.

Complex Attack Vectors
Forensic analysis identified two likely intrusion vectors: a malicious code repository and a TestFlight application. A known vulnerability in VSCode and Cursor editors may have enabled silent code execution.
Drift immediately suspended all protocol functions. Mandiant was engaged for investigation.

Aftermath and Recovery
Drift's native token plunged from $0.07 to around $0.03. The team began sending on-chain messages to wallets holding stolen crypto.
The attack was attributed with medium-high confidence to UNC4736. Such long-con, identity-rich operations expose deep weaknesses in multisig-based security.