Drift Links $280 Million Exploit to Radiant Hack Actors

Drift Links $280 Million Exploit to Radiant Hack Actors

N
News Editor 01
2026-07-24 09:30:15
Drift said its April 1 exploit followed roughly six months of trust-building and social engineering, and it linked the case with medium-high confidence to the actors behind Radiant Capital’s 2024 hack.

Drift Protocol said the April 1 exploit was the result of a long-running campaign rather than a one-off breach. External estimates put losses at about $280 million. In its early review, the team said the operation showed signs of organizational support, dedicated resources, and months of deliberate preparation.

According to Drift, the first contact began around October 2025. People claiming to represent a quantitative trading firm approached contributors at a major crypto conference and said they wanted to integrate with the protocol. Over the next six months, those individuals continued meeting contributors at several industry events. Drift said the people involved were technically capable, understood how the protocol worked, and appeared to have legitimate professional backgrounds.

Months of trust-building led to compromised contributor devices

Drift said repeated in-person contact helped the group build credibility over time. After establishing that trust, the attackers sent malicious links and tools to contributors, which were then used to compromise devices, execute the exploit, and remove traces of activity after the breach. The sequence described by the team points to a staged intrusion, moving from relationship-building to technical compromise.

The exchange also said it has medium-high confidence that the same actors behind the October 2024 Radiant Capital hack were responsible. That earlier incident caused losses of about $58 million and also involved malware used to gain access to internal systems. In December 2024, Radiant Capital said a North Korea-aligned hacker had posed as a former contractor and sent malware through Telegram. The firm said a ZIP file later circulated among developers for feedback and became the path into the intrusion.

Crypto conferences highlighted as a possible attack surface

Drift said the people who met contributors in person “were not North Korean nationals.” At the same time, the team noted that DPRK-linked threat actors often rely on third-party intermediaries for face-to-face contact and long-term relationship building. Drift is now working with law enforcement and other crypto industry participants to assemble a full record of the April 1 attack.

The case adds to security concerns around conferences and direct industry meetings, where threat groups may observe teams, gain trust, and prepare later attacks through offline contact before moving to malware or phishing tools.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.