|
News North Korean hackers steal $285M from crypto exchange in largest heist this yearDrift Protocol says DPRK-linked actors spent at least six months infiltrating its platform before carrying out attack North Korean cybercriminals stole at least $285 million from a decentralized cryptocurrency exchange last week after an elaborate six-month operation to infiltrate the platform, marking the largest heist of its kind so far this year. The attackers targeted Drift Protocol, a crypto exchange built on the Solana blockchain, on April 1, blockchain analytics firms TRM Labs and Elliptic reported the following day. Both firms attributed the theft to the DPRK, placing the total haul at $285 and $286 million, respectively. It took the threat actors around 12 minutes to drain user assets, with most stolen funds moved from the Solana blockchain to Ethereum within hours, according to TRM. Drift Protocol also confirmed the breach on April 2, warning users that it was not an “April Fools joke” but an active attack. The heist was the largest decentralized finance hack to date in 2026 and the second-largest in Solana’s history, after the $326 million Wormhole bridge attack in 2022, according to TRM and Elliptic. BUILDING TRUST Drift Protocol attributed the attack “with medium-high confidence” to North Korea, specifically to the threat actor known as UNC4736 (also tracked as AppleJeus or Citrine Sleet). The threat group was previously linked to the Radiant Capital hack in Oct. 2024. Several features point in North Korea’s direction, according to the platform, including fund flows to stage and test the operation that “trace back to the Radiant attackers” and the use of personas that overlap with “known DPRK-linked activity.” ![]() Drift Protocol said the attackers laid the groundwork for the attack at least six months in advance, including by directly approaching contributors to the platform at a cryptocurrency conference and posing as a quantitative trading firm looking to integrate on the protocol. However, the individuals who interacted with the platform’s contributors in person “were not North Korean nationals.” “DPRK threat actors operating at this level are known to deploy third-party intermediaries to conduct face-to-face relationship-building,” it explained. The individuals were tech savvy, had “verifiable professional backgrounds” and were familiar with the platform, according to Drift Protocol. They earned the exchange’s trust by depositing over $1 million and eventually built what Drift Protocol described as a “functioning operational presence” inside the platform’s ecosystem. Further face-to-face meetings with these individuals continued until the attack on April 1. “Right as the exploit happened, their Telegram chats and malicious software had been completely scrubbed,” the platform said. While it is still investigating the heist, Drift Protocol theorized that a member of its team was compromised after downloading a malicious code repository shared by the attackers and disguised as a legitimate project. Another team member appears to have been tricked into installing a fake wallet app. CASHING IN TRM traced the beginning of the hack to a March 11 “withdrawal of 10 ether (some $20,000) from Tornado Cash,” a cryptocurrency mixer that North Korean cybercriminals are known to use to conceal stolen funds. These funds were moved hours later to fund the deployment of the fake CarbonVote Token (CVT) that they then “used to manipulate Drift,” the firm said. The attackers relied on “durable nonce” accounts created from March 23-30, a legitimate workaround in Solana that allows transactions to be pre-signed and executed later without expiring. They also induced Drift Protocol contributors to “pre-sign” transactions that looked routine but had hidden permissions for “critical admin actions.” Around the same time, Drift changed its approval protocol to eliminate a delay in processing transactions “that would have allowed detection and intervention.” ![]() The attackers spent weeks manufacturing legitimacy for CVT by creating “750 million units” and buying and selling the fake asset to create the pretense of legitimate trading activity. “Drift’s oracles picked up that artificial signal and treated CVT as a real asset,” TRM said. When April 1 came, the attackers deployed the pre-signed transactions, listed CVT as “valid collateral on Drift, raised withdrawal limits to extreme levels and deposited hundreds of millions in CVT against that manufactured price,” the firm explained. In around 12 minutes, 31 withdrawal transactions went through, draining real assets and leading the exchange to suspend transactions. Each transaction moved hundreds of thousands or millions of the USDC stablecoin pegged to the U.S. dollar, “far outstripping the speed and aggressiveness of even the Bybit laundering of 2025,” TRM said, referring to North Korea’s largest-ever cryptocurrency heist. Elliptic wrote that the threat actors targeted three wallets and that the largest single transfer involved tokens worth $155 million at the time of the theft. TRM observed that the price of the Drift Protocol’s CVT token “fell over 40%” as a result of the heist. “The confidence of the hackers was staggering,” the firm said. Edited by Bryan Betts © Korea Risk Group. All rights reserved. |







