Elliptic Flags North Korea Link in $285 Million Drift Protocol Theft

Elliptic Flags North Korea Link in $285 Million Drift Protocol Theft

N
News Editor 01
2026-07-23 19:50:15
Elliptic said the $285 million Drift Protocol theft shares blockchain patterns, laundering methods, and technical signals seen in past attacks tied to North Korean actors. Funds moved from Solana across multiple chains, making tracing harder.
Drift ProtocolEllipticNorth Korea hackerson-chain securitycross-chain laundering

Blockchain analytics firm Elliptic said its latest investigation found that the $285 million theft tied to Drift Protocol showed blockchain behavior, laundering techniques, and technical indicators that closely resemble methods used in earlier state-backed cyberattacks, raising suspicion of involvement by groups linked to North Korea.

Wallet setup and test transactions point to planning

According to the report, the stolen assets were moved quickly after the breach through a network of separate wallets and then dispersed across many more addresses within a short period. Investigators also identified test transactions and the creation of bespoke wallets before the attack. Those details suggest a coordinated operation with preparation in place before the exploit was carried out.

Elliptic said that if North Korean involvement is officially confirmed, the incident would become the 18th major cyberattack attributed by the firm to North Korean actors this year. It also estimates that more than $300 million in digital assets has been stolen through similar methods since the start of 2024.

From Solana to other chains, the trail became harder to follow

The research found that the stolen funds were rapidly consolidated and shifted across multiple blockchains, which made the money trail harder to reconstruct. The assets originated on Solana and were then quickly swapped into different token types on Ethereum and other networks. That sequence showed a sophisticated understanding of cross-chain movement and token conversion.

Elliptic noted that Solana’s structure, where different asset types are assigned separate accounts, adds another layer of opacity. Activity linked to one actor can appear fragmented across multiple addresses. For analysts, that turns the tracing process into a puzzle spread across different locations.

Account clustering tied dozens of assets to one attacker group

To address that issue, Elliptic said it used an account clustering methodology to group related token accounts and map illicit flows more clearly. The firm said this method was key to showing that dozens of distinct asset types were ultimately controlled by the same group of attackers.

Elliptic also wrote that actors linked to North Korea have seized large amounts of digital assets in recent years, and international investigators increasingly believe those funds are directed into the country’s nuclear weapons program. A separate study released in December 2024 said North Korea-backed hacking campaigns had accelerated, with digital asset theft in the prior year alone nearing $2 billion. The U.S. Department of the Treasury has also stated that much of this cybercrime revenue appears to finance North Korea’s weapons of mass destruction programs.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.