$280M Drift Protocol Hack Linked to Six-Month North Korean Operation
Drift Protocol lost approximately $280 million to a six-month-long North Korean operation. The attack began at a major crypto conference in fall 2025 and continued through various meetings with Drift contributors until February 2026. The attackers presented themselves as representatives of a quantitative trading firm, gaining the trust of the protocol's team.
After onboarding an Ecosystem Vault and depositing over $1 million of their own capital, the group induced two contributors to compromise their devices through different vectors. One contributor was tricked into installing a pre-release app via Apple's TestFlight platform, while another was compromised after cloning a code repository shared by the group.
The attackers used the compromised devices to obtain multisig approvals and execute a durable nonces attack on April 1, draining the protocol in under a minute. The operation is linked to UNC4736, also known as AppleJeus or Citrine Sleet, a North Korean state-affiliated group previously associated with the Radiant Capital hack.
The individuals involved in the operation were not North Korean nationals, but rather third-party intermediaries with constructed professional identities designed to pass due diligence checks. Drift has frozen all remaining protocol functions and removed compromised wallets from the multisig.