Full story
Elaborate Infiltration
Drift Protocol was hacked for $270 million in a six-month North Korean intelligence operation.
“A North Korean state-linked group spent roughly six months infiltrating Drift Protocol under the guise of a quantitative trading firm”
Attackers posed as a quantitative trading firm, meeting contributors in person across multiple countries.

They deposited over $1 million of their own capital and integrated an Ecosystem Vault.
The exploit did not stem from a smart contract bug but from compromised administrative controls.
Complex Attack Vectors
Forensic analysis identified two likely intrusion vectors: a malicious code repository and a TestFlight application.
A known vulnerability in VSCode and Cursor editors may have enabled silent code execution.

Drift immediately suspended all protocol functions.
Mandiant was engaged for investigation.
Aftermath and Recovery
Drift's native token plunged from $0.07 to around $0.03.
“Drift said in a post that it had sent messages on Ethereum’s network to four wallets holding massive amounts of stolen crypto”
The team began sending on-chain messages to wallets holding stolen crypto.
The attack was attributed with medium-high confidence to UNC4736.
Such long-con, identity-rich operations expose deep weaknesses in multisig-based security.
