Blockchain analytics firm Elliptic said the $286 million exploit of Solana-based perpetuals protocol Drift Protocol carries multiple indicators consistent with North Korean state-backed hackers. In a report released Thursday, the firm said the attacker’s behavior—from early testing transactions to wallet setup and rapid post-exploit fund movement—followed a highly organized pattern.
Preparation began before the main exploit
Rather than focusing on the technical flaw in Drift’s smart contracts, Elliptic examined how the attacker operated. According to the report, the exploiter conducted test transactions ahead of the main attack and pre-positioned wallets to receive stolen funds. Once the exploit succeeded, the assets were quickly consolidated, swapped, moved across bridges to other blockchains, and converted into more liquid holdings.
Elliptic said this kind of structured and repeatable laundering flow is designed to obscure the source of funds while preserving control over the assets. The firm added that the pattern closely matches methods seen in previous North Korean operations.
Solana’s account structure made tracing harder
Elliptic identified Solana’s account model as a central obstacle in the investigation. On Solana, each asset is stored in a separate token account, which can make one attacker’s activity appear scattered across a large number of addresses. That fragmentation makes it difficult to reconstruct the full trail by looking at addresses one by one.
To deal with that, Elliptic highlighted its clustering approach. The technique links multiple token accounts back to a single entity, allowing investigators to follow funds across chains even when the laundering process involves more than a dozen different assets.
Token losses deepened as DPRK-linked cases added up
The report said Drift token holders have already taken a severe hit. Since the attack, DRIFT has fallen more than 40% to about $0.06. If authorities ultimately confirm North Korean involvement, the incident would become the 18th DPRK-linked attack tracked by Elliptic this year, pushing the total stolen in such cases past $300 million.
The source material also cited an earlier Chainalysis report saying North Korean hackers stole a record $2 billion in crypto in 2025, up 51% from the previous year, including the Bybit theft. Last month, the U.S. Treasury said North Korea has been using stolen crypto assets to fund its weapons of mass destruction program.

