COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Drift Protocol freezes operations after months-long infiltration linked to North Korea
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > DeFi News > Drift Protocol freezes operations after months-long infiltration linked to North Korea
DeFi News

Drift Protocol freezes operations after months-long infiltration linked to North Korea

In Brief

  • Drift Protocol suspended all functions after a long-term infiltration later tied to North Korea.

  • Attackers built fake identities and gained trust through months of in-person and online contact.

  • Three technical attack vectors were found, including a silent code execution exploit in key code editors.
Ömer Ergin
Ömer Ergin 4 weeks ago
Share
SHARE

Drift Protocol, a decentralized derivatives exchange operating on Solana, suspended all activities on April 1, 2026, after uncovering a sophisticated attack orchestrated over several months. Forensic investigations have pointed to the involvement of a North Korean state-backed cyber group, marking one of the most structured infiltration efforts ever seen in decentralized finance. Established in 2021, Drift is known for providing leverage trading and innovative liquidity solutions, positioning it as a key player in the expanding Solana DeFi ecosystem.

Contents
A coordinated social engineering effortTechnical attack vectors and attribution

A coordinated social engineering effort

The breach traces back to autumn 2025, when Drift contributors were initially contacted at a major international crypto event. The individuals presented themselves as representatives of a quantitative trading firm seeking collaboration for an institutional vault integration with Drift.

Team members reported that the attackers maintained a convincing and technically proficient presence, meeting contributors in person at a series of industry conferences across several countries over a six-month period.

Early on, a dedicated Telegram group was created to continue discussions on product features and integration strategies. Over the following months, the group consistently participated in remote working sessions and detailed conversations about trading infrastructure.

In December 2025, the attackers managed to onboard an Ecosystem Vault within Drift Protocol, depositing over $1 million in capital and deepening engagement with the core team. They continued to contribute input and resources throughout early 2026, heightening their perceived trustworthiness.

Drift’s internal review later revealed that the individuals responsible had constructed elaborate identities, complete with verifiable professional backgrounds, employment histories, and social media activity to reinforce their legitimacy.

Product discussions continued through March 2026, allowing the attackers to build credibility and routine contact with key contributors, which laid the groundwork for the exploit.

Technical attack vectors and attribution

After discovering the exploit on April 1, the team began collaboration with digital forensics firms, including Mandiant, to investigate device logs and digital traces. The review identified three primary attack vectors enabling unauthorized code execution on contributor devices.

One vector involved malicious code in a repository shared under the guise of vault frontend development, designed to silently execute arbitrary code immediately upon opening with editors such as VSCode or Cursor. Another vector centered on persuading a contributor to install a TestFlight app claimed to function as a custom wallet product.

Investigations revealed that no warning prompts, permissions, or visible indicators alerted users to the presence of malware during these attacks. The perpetrators deleted all related Telegram messages and software artifacts immediately after initiating the exploit.

The SEAL911 incident response team attributed the campaign, with medium-high confidence, to UNC4736—a North Korean state-affiliated cyber group also tracked under the names AppleJeus or Citrine Sleet, noted for prior DeFi and wallet infrastructure operations.

Connections have emerged between this campaign and past incidents, such as the October 2024 Radiant Capital breach. To obscure their involvement, threat actors reportedly engaged third-party intermediaries for in-person meetings with protocol contributors, rather than sending DPRK nationals directly.

Drift Protocol has urged other projects to reassess access controls, thoroughly vet all software dependencies, and remain vigilant against well-orchestrated social engineering attempts targeting the decentralized finance sector.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

RsETH hacked for $300 million, 116,500 tokens exploited

Kelp DAO hack exposes $300 million hole in rsETH

Aave raises $160 million after $200 million DeFi hack

Defi reels from $13 billion TVL drop after KelpDAO attack

Mythos AI exposes $1 billion risk in DeFi via DOT

Ömer Ergin 5 April, 2026 - 12:55 pm 5 April, 2026 - 12:55 pm
Share This Article
Facebook Twitter
Share
Previous Article Cryptocurrencies pressured by geopolitical tension as investors brace for further declines
Next Article Crypto prices move with investor sentiment as quantum and DeFi security concerns shape the outlook for ETH, SOL, BTC, USDC, PIPPIN, and LINK
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Shiba Inu gains 30 percent since February, eyes key resistance
Shiba (SHIB)
Shinhan Card launches Solana payment trial for 28 million users
Solana (SOL)
XRP gets institutional boost as 65% eye CLARITY Act
Ripple (XRP)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?