Blockchain analytics firm Elliptic said its latest investigation found that the $285 million theft tied to Drift Protocol showed blockchain behavior, laundering techniques, and technical indicators that closely resemble methods used in earlier state-backed cyberattacks, raising suspicion of involvement by groups linked to North Korea.
Wallet setup and test transactions point to planning
According to the report, the stolen assets were moved quickly after the breach through a network of separate wallets and then dispersed across many more addresses within a short period. Investigators also identified test transactions and the creation of bespoke wallets before the attack. Those details suggest a coordinated operation with preparation in place before the exploit was carried out.
Elliptic said that if North Korean involvement is officially confirmed, the incident would become the 18th major cyberattack attributed by the firm to North Korean actors this year. It also estimates that more than $300 million in digital assets has been stolen through similar methods since the start of 2024.
From Solana to other chains, the trail became harder to follow
The research found that the stolen funds were rapidly consolidated and shifted across multiple blockchains, which made the money trail harder to reconstruct. The assets originated on Solana and were then quickly swapped into different token types on Ethereum and other networks. That sequence showed a sophisticated understanding of cross-chain movement and token conversion.
Elliptic noted that Solana’s structure, where different asset types are assigned separate accounts, adds another layer of opacity. Activity linked to one actor can appear fragmented across multiple addresses. For analysts, that turns the tracing process into a puzzle spread across different locations.
Account clustering tied dozens of assets to one attacker group
To address that issue, Elliptic said it used an account clustering methodology to group related token accounts and map illicit flows more clearly. The firm said this method was key to showing that dozens of distinct asset types were ultimately controlled by the same group of attackers.
Elliptic also wrote that actors linked to North Korea have seized large amounts of digital assets in recent years, and international investigators increasingly believe those funds are directed into the country’s nuclear weapons program. A separate study released in December 2024 said North Korea-backed hacking campaigns had accelerated, with digital asset theft in the prior year alone nearing $2 billion. The U.S. Department of the Treasury has also stated that much of this cybercrime revenue appears to finance North Korea’s weapons of mass destruction programs.

