Drift Protocol said the April 1 exploit was the result of a long-running campaign rather than a one-off breach. External estimates put losses at about $280 million. In its early review, the team said the operation showed signs of organizational support, dedicated resources, and months of deliberate preparation.
According to Drift, the first contact began around October 2025. People claiming to represent a quantitative trading firm approached contributors at a major crypto conference and said they wanted to integrate with the protocol. Over the next six months, those individuals continued meeting contributors at several industry events. Drift said the people involved were technically capable, understood how the protocol worked, and appeared to have legitimate professional backgrounds.
Months of trust-building led to compromised contributor devices
Drift said repeated in-person contact helped the group build credibility over time. After establishing that trust, the attackers sent malicious links and tools to contributors, which were then used to compromise devices, execute the exploit, and remove traces of activity after the breach. The sequence described by the team points to a staged intrusion, moving from relationship-building to technical compromise.
The exchange also said it has medium-high confidence that the same actors behind the October 2024 Radiant Capital hack were responsible. That earlier incident caused losses of about $58 million and also involved malware used to gain access to internal systems. In December 2024, Radiant Capital said a North Korea-aligned hacker had posed as a former contractor and sent malware through Telegram. The firm said a ZIP file later circulated among developers for feedback and became the path into the intrusion.
Crypto conferences highlighted as a possible attack surface
Drift said the people who met contributors in person “were not North Korean nationals.” At the same time, the team noted that DPRK-linked threat actors often rely on third-party intermediaries for face-to-face contact and long-term relationship building. Drift is now working with law enforcement and other crypto industry participants to assemble a full record of the April 1 attack.
The case adds to security concerns around conferences and direct industry meetings, where threat groups may observe teams, gain trust, and prepare later attacks through offline contact before moving to malware or phishing tools.

