North Korean Hackers Spent Six Months Infiltrating Drift Protocol, Stole $270M

North Korean Hackers Spent Six Months Infiltrating Drift Protocol, Stole $270M

N
News Editor 01
2026-07-23 02:20:14
Drift Protocol revealed the $270 million exploit was a six-month intelligence operation by North Korean state-affiliated group UNC4736. Attackers posed as a quant trading firm, used social engineering, VSCode flaws and TestFlight malware to execute the heist.
Drift ProtocolNorth Korean hackerscrypto theftsocial engineeringDeFi security

Drift Protocol's detailed incident update on Sunday confirmed that the $270 million exploit on April 1 was the result of a six-month intelligence operation carried out by a North Korean state-affiliated hacking group tracked as UNC4736 (also known as AppleJeus or Citrine Sleet).

From Conference to Trust: Six Months of Social Engineering

The attackers first made contact in fall 2025 at a major crypto conference, presenting themselves as a quantitative trading firm seeking integration with Drift. They were technically fluent, had verifiable professional backgrounds, and understood the protocol's inner workings. A Telegram group was formed, and months of substantive conversations around trading strategies and vault integrations followed—standard onboarding interactions for trading firms entering DeFi protocols.

Between December 2025 and January 2026, the group deployed an Ecosystem Vault on Drift, held multiple working sessions with contributors, deposited over $1 million of their own capital, and built a functioning operational presence inside the ecosystem. Drift contributors even met individuals from the group face-to-face at major industry conferences across several countries through February and March. By the time the attack launched on April 1, the relationship was nearly half a year old.

Double Attack Vector: VSCode Vulnerability and TestFlight Trap

The compromise came through two vectors. First, via a GitHub repository: attackers sent code repository links to Drift contributors, exploiting a known vulnerability in VSCode and Cursor editors that the security community had flagged since late 2025. Simply opening a file or folder in the editor silently executed arbitrary code without any prompt or warning. Second, a TestFlight application downloaded under the guise of a wallet product. Apple's pre-release app distribution platform bypasses App Store security review. Once devices were compromised, the attackers obtained the two multisig approvals needed to execute a durable nonce attack. Those pre-signed transactions sat dormant for over a week before being activated on April 1, draining $270 million from the protocol's vaults in under a minute.

Third-Party Intermediaries: DPRK's Signature Tactic

Drift's attribution points to UNC4736 based on on-chain fund flows tracing back to the Radiant Capital attackers and operational overlap with known DPRK-linked personas. However, the individuals who appeared in person at conferences were not North Korean nationals. High-level DPRK threat actors deploy third-party intermediaries with fully constructed identities, employment histories, and professional networks built to withstand due diligence.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.