DEVELOPING | 7 sources | 5 publications | Momentum: 3.1/day | Last update: 2h ago

Timeline

  • Six months prior to April 2026: North Korean actors initiate social engineering operation, posing as a trading firm and meeting Drift contributors in person across multiple countries
  • Early operation phase: Attackers deposit $1 million of their own capital into Drift Protocol to establish legitimacy
  • April 1, 2026: Attackers execute the exploit, draining the protocol in approximately 12 minutes
  • April 3, 2026: Blockchain analytics firms Elliptic and TRM Labs identify attack patterns consistent with North Korean state-sponsored groups
  • April 5, 2026: Drift Protocol and SEAL 911 team publicly attribute the attack to North Korean actors with "medium-high" confidence

Key Data Points

  • Total amount stolen: $270 million to $285 million (sources vary between $270M, $280M, and $285M)
  • Duration of social engineering operation: Six months
  • Time to execute drain: Approximately 12 minutes on April 1, 2026
  • Attackers' initial capital deposit: $1 million
  • Confidence level of attribution: Medium-high
  • Previous linked attack: Radiant Capital hack in October 2024, which netted $58 million
  • Target platform: Drift Protocol, Solana's largest decentralized perpetual futures exchange

What We Know

Drift Protocol and the SEAL 911 security team have attributed a $270 million exploit to North Korean state-sponsored actors with medium-high confidence, linking the operation to the same group responsible for the October 2024 Radiant Capital hack that stole $58 million. The attackers executed a sophisticated six-month social engineering campaign, posing as representatives of a legitimate trading firm and meeting Drift contributors face-to-face in multiple countries. To establish credibility, the threat actors deposited $1 million of their own capital into the protocol before executing the attack.

The actual exploit took place on April 1, 2026, with attackers draining the protocol in approximately 12 minutes. Blockchain analytics firms Elliptic and TRM Labs independently identified attack patterns consistent with North Korean state-sponsored hacking groups. The operation targeted Drift Protocol, Solana's largest decentralized perpetual futures exchange, demonstrating a level of operational sophistication and patience unusual even for state-backed threat actors.

What's Unclear

Sources report conflicting figures for the total amount stolen, ranging from $270 million to $285 million. The exact mechanism of the exploit has not been detailed in available reporting. While attribution to North Korea carries medium-high confidence, the specific technical evidence supporting this attribution and the precise identity of the threat group within North Korea's cyber apparatus remain undisclosed. It is also unclear how the six-month social engineering operation specifically facilitated the technical exploit, whether it involved compromised credentials, malware injection, or other attack vectors. The current status and location of the stolen funds have not been reported.

Watch For

  • Movement of stolen funds through mixers or cross-chain bridges, which would indicate laundering operations beginning
  • Additional technical details about the exploit mechanism and how the social engineering enabled it
  • Official government attribution from U.S. or allied intelligence agencies, which would elevate confidence beyond medium-high
  • Evidence of similar long-term social engineering operations targeting other DeFi protocols
  • Regulatory response from U.S. Treasury or OFAC, potentially including new sanctions or guidance
  • Whether Drift Protocol announces a recovery plan or compensation strategy for affected users

Sources (7 articles)

  • Drift links $280 million exploit to six-month social engineering op run by suspected North Korean actors
    RWA Times (2026-04-05) — Original source
  • Drift links $280 million exploit to six-month social engineering op run by suspected North Korean actors
    The Block (2026-04-05) — Original source
  • Drift says $270 million exploit was a six-month North Korean intelligence operation
    CoinDesk (2026-04-05) — Original source
  • Drift Protocol $280M Breach: Months of Deliberate Preparation
    RWA Times (2026-04-05) — Original source
  • Drift Protocol Exploit Took 'Months Of Deliberate Preparation'
    RWA Times (2026-04-05) — Original source
  • Drift Protocol $280M exploit took 'months of deliberate preparation'
    CoinTelegraph (2026-04-05) — Original source
  • North Korean Hackers Suspected in $285 Million Drift Protocol Heist
    Unchained (2026-04-03) — Wire analysis | Original source

This intelligence brief is auto-generated from 7 source articles tracked by The Fourth Web pipeline. Updated as new sources arrive. Browse all intel briefs.