logo
  • menu
  • Markets
  • ETFs
  • Live
  • Spot
  • Futures
  • Learn
  • Sign In
  • Sign Up
  • Downloads
  • English
  • |
  • USD
  • |
Sign Up
Crypto PricesLearnLatest NewsDownloadsMarketsSpotAnnouncements
Home/
Latest News/
Live

North Korean Hackers Spent Six Months Infiltrating Drift Before $285M Exploit

By Decrypt
Apr 6, 2026
4.7 
★
★
★
★
★
★
★
★
★
★
 316 User Rating
Share

"Crypto teams are now facing adversaries that operate more like intelligence units than hackers, and most organizations are not structurally prepared for that level of threat,” Michael Pearl, VP of Strategy at blockchain security firm Cyvers, told Decrypt.

Drift said the group first approached contributors at a major crypto conference last fall, presenting as a quantitative trading firm seeking to integrate with the protocol.

Over months, the group built trust through in-person meetings, Telegram coordination, onboarded an Ecosystem Vault on Drift, and made a $1 million vault deposit of their own capital, only to vanish, with chats and malware “completely scrubbed” when the exploit hit.

The DEX said the intrusion may have involved a malicious code repository, a fake TestFlight app, and a VSCode/Cursor vulnerability that enabled silent code execution without user interaction.

Radiant Capital’s $50M Breach Among ‘Most Sophisticated Hacks’ in DeFi History

Drift said the individuals who met contributors in person were not North Korean nationals, noting that DPRK-linked actors often rely on third-party intermediaries for “face-to-face engagement.”

Onchain fund flows and overlapping personas point to DPRK-linked actors, according to incident responders SEAL 911, though Mandiant has yet to confirm attribution pending forensics, the platform noted.

Security researcher @tayvano_, one of the experts whom Drift credited for assistance in identifying the malicious actors, suggested the exposure extend well beyond this incident.

Industry implications

"Drift and Bybit highlight the same pattern — signers were not directly compromised at the protocol level, they were tricked into approving malicious transactions," Pearl noted. "The core issue is not the number of signers, but the lack of understanding of transaction intent."

“Security must shift to pre-transaction validation at the blockchain level, where transactions are independently simulated and verified before execution,” Pearl said, adding that once attackers control what users see, the only effective defense is validating what a transaction actually does, regardless of the interface.

On developer tools as an attack surface, Lavid said the assumption has to change from the ground up.

'We Are Ready to Speak': Drift Beckons North Korea-Linked Hackers Following $285M Exploit

"You have to assume the endpoint is compromised," he told Decrypt, pointing to IDEs, code repositories, mobile apps, and signer environments as increasingly common entry points.

“If these foundational tools are vulnerable, anything shown to the user—including transactions—can be manipulated,” the expert said, noting this “fundamentally breaks traditional security assumptions,” leaving teams unable to trust “the interface, the device, or even the signing flow.”

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of BitKan. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. BitKan shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. Products mentioned in this article may not be available in your region.

Latest News

Industry

Cryptocurrency

Airdrop

Markets

  • SpaceX Prices Record $75B IPO at $135, Hits $1.8T Valuation

    SpaceX Prices Record $75B IPO at $135, Hits $1.8T Valuation

    SpaceX has officially executed the largest initial public offering in Wall Street history, substantially eclipsing all previous market records.
    Wayne Ingram
    Jun 12, 2026
  • Stablecoin Secondary Market Rules Pit Banks Against Crypto

    Stablecoin Secondary Market Rules Pit Banks Against Crypto

    The Bank Policy Institute and The Clearing House want anti-money laundering rules to cover secondary market activity.
    Martha Grizzard
    Jun 12, 2026
  • VerifiedX Launches Bitcoin Sidechain for Native DeFi Privacy

    VerifiedX Launches Bitcoin Sidechain for Native DeFi Privacy

    VerifiedX has officially introduced a decentralized "reliever chain" designed to bring programmable, privacy-preserving functionality to the Bitcoin network.
    Martha Grizzard
    May 18, 2026
  • Japan’s SBI and Rakuten Plan Crypto Trusts as Rules Finalize

    Japan’s SBI and Rakuten Plan Crypto Trusts as Rules Finalize

    SBI Securities and Rakuten Securities have officially announced plans to introduce cryptocurrency investment trusts to their massive retail user bases.
    Craig Green
    May 18, 2026
  • Senate Advances CLARITY Act: A New Era for U.S. Crypto Oversight

    Senate Advances CLARITY Act: A New Era for U.S. Crypto Oversight

    The Senate Banking Committee advanced the CLARITY Act on May 14, 2026 to establish a comprehensive federal framework for the digital asset industry.
    May 15, 2026
View more data 
BTCBTC(BTC)
$0
--(Last 24h)
SpotFutures

Top

View more
  1. 1S&P 500 Reclaims 200-Day Moving Average, Bitcoin Gains
  2. 2Trump Softens His Stance on Reciprocal Tariffs, US Stocks and Crypto Markets Rise
  3. 3Vitalik Buterin : The current price of ETH has not been affected by the merger event
  4. 4Vibhu Norby : Solana Spaces store to bring 100K people to Solana per month
  5. 5CZ: compared with the record high nine months ago, the current situation of the industry is much better

Top Gainers

View more
Superp
SuperpSUP

$0.003745

+103.31%
Bitway
BitwayBTW

$0.1290

+99.53%
Biconomy
BiconomyBICO

$0.0419

+87.57%
Re
ReRE

$0.8810

+83.47%
SuperRare
SuperRareRARE

$0.0170

+36.00%

Top Trending

View more
Biconomy
BiconomyBICO

$0.0420

+88.11%
Bitway
BitwayBTW

$0.1290

+99.53%
Re
ReRE

$0.8811

+83.49%
Ethereum
EthereumETH

$1,725.19

+1.92%
Litecoin
LitecoinLTC

$44.2000

+1.61%

Recently added

View more
Ambire AdEx
Ambire AdExADX

$0.0610

+1.50%
Re
ReRE

$0.8811

+83.49%
o1.exchange
o1.exchangeO

$0.8566

+34.90%
SpaceX
SpaceXSPCXB

$180.990

+0.70%
Jotchua
JotchuaJOTCHUA

$0.004651

-18.52%

Learn

View more
  1. 1What Is Rehypothecation Risk in Crypto? How to Protect Yourself
  2. 2What Is pERC20? How Does This Ethereum Token Standard Work?
  3. 3What Are Crypto Prediction Markets? A Complete Guide for Beginners
  4. 4What is the MSX X Card? Understanding the New Crypto Card
  5. 5How Does The SpaceX IPO Impact Crypto? Are Traders Selling Bitcoin for SpaceX?
About Us
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
English
About Us
+
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
+
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
+
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
+
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
+
  • Twitter
  • Facebook
  • Telegram
  • YouTube
  • Instagram
  • Medium
  • Linkedin
@2012-2026 BITKAN.com