Drift Protocol, the largest decentralized perpetual futures exchange on Solana, lost $285 million in user assets on April 1, 2026, in what investigators now confirm as a six-month social engineering operation by North Korean state-backed hackers. Blockchain analytics firms TRM Labs and Elliptic have attributed the attack to UNC4736, a threat group also tracked as AppleJeus and Citrine Sleet, with medium-high confidence. The breach ranks as the largest DeFi exploit of 2026 and the second-largest in Solana’s history, behind only the $326 million Wormhole bridge hack of 2022.
- Attackers drained $285 million from Drift Protocol’s vaults in 12 minutes on April 1, 2026, stealing 41.7 million JLP tokens, USDC, SOL, and BTC derivatives.
- TRM Labs and Elliptic traced the operation to UNC4736, a North Korean state-affiliated threat actor responsible for over $6.5 billion in crypto theft.
- The attack relied on social engineering, not a smart contract bug. Operatives posed as a trading firm for six months, compromising multisig signers through conference meetings and malicious code repositories.
- Stolen funds were bridged to Ethereum within hours using cross-chain swaps and converted to ETH, following patterns seen in previous DPRK operations.
Published: April 6, 2026 08:00 UTC
How the infiltration started
The operation began in fall 2025 when individuals posing as a quantitative trading company approached Drift contributors at cryptocurrency conferences across multiple countries. Over six months, they built trust through detailed technical discussions about trading strategies and vault integrations. The people who appeared at these events were not North Korean nationals. DPRK threat actors at this level are known to use third-party intermediaries for face-to-face relationship building, according to TRM Labs’ investigation.
Between December 2025 and January 2026, the group deposited over $1 million into an Ecosystem Vault on Drift to establish operational credibility. Integration conversations continued through February and March 2026, giving the attackers sustained access to Drift’s contributor network.

How the attack was executed
On-chain staging began March 11 with a 10 ETH withdrawal from Tornado Cash. Those funds moved at approximately 12:00 AM GMT on March 12, which corresponds to 9:00 AM Pyongyang time, and were used to deploy CarbonVote Token (CVT). The attackers minted 750 million CVT units, seeded a few thousand dollars in liquidity on Raydium, and used wash trading to build an artificial price history near $1. Drift’s oracles picked up that fabricated signal and treated CVT as a legitimate asset.
Two compromise vectors infected Drift contributors. One contributor was likely compromised after cloning a malicious code repository that weaponized Visual Studio Code’s tasks.json to execute malicious code automatically when opening the project. A second contributor was persuaded to download a wallet application through Apple’s TestFlight, which installed compromised software. The attackers deleted their Telegram chats and malware around the time of the attack, according to The Hacker News.
On March 27, Drift migrated its Security Council to a 2-of-5 multisig threshold with zero timelock, eliminating the protocol’s last detection window. Pre-signed transactions that appeared routine actually carried hidden authorizations for admin actions. On April 1, 31 withdrawal transactions completed in roughly 12 minutes, draining three core vaults: JLP Delta Neutral, SOL Super Staking, and BTC Super Staking.
Where the money went
The stolen assets included 41.7 million JLP tokens worth approximately $155 million, plus USDC, SOL, cbBTC, wBTC, and liquid staking tokens totaling $286 million. Most of the funds were bridged to Ethereum within hours, converted to ETH through decentralized exchanges, following laundering patterns Elliptic has documented in previous DPRK operations. The cross-chain movement from Solana to Ethereum is consistent with how North Korean actors laundered proceeds from the $1.5 billion Solana ecosystem and other major exploits.
North Korean cyber units have now stolen over $6.5 billion in crypto assets in recent years, according to U.S. government estimates. The funds are believed to support the country’s weapons programs. This attack is the eighteenth suspected DPRK operation in 2026 alone, with combined losses exceeding $300 million for the year.
What DeFi protocols should learn
The root cause was not a smart contract vulnerability. TRM Labs identified three procedural failures: removal of timelocks on governance actions that eliminated detection windows, oracle design that lacked minimum liquidity thresholds and time-weighted price validation, and multisig signers who did not have verification processes for transaction content. Drift has engaged Mandiant for forensic investigation and is working with law enforcement, though formal device forensics are still underway.
CrowdStrike has noted that North Korea’s cyber operations have become deliberately compartmentalized, splitting work across espionage units (Kimsuky), financial operations (Lazarus Group), and disruption teams (Andariel). The Drift attack matches the financial operations playbook, where DPRK actors target crypto platforms through long-term social engineering rather than code exploits.
For DeFi protocols handling hundreds of millions in user deposits, the lesson is direct: timelocks on admin actions, oracle circuit breakers, and operational security training for anyone with signing authority are not optional. The next DPRK operation is likely already in its relationship-building phase.
FAQ
What is Drift Protocol and why was it targeted?
Drift Protocol is a decentralized perpetual futures exchange built on the Solana blockchain. It was the largest such platform on Solana by total value locked. North Korean hackers targeted it because of the large pool of user deposits in its vaults, which held over $285 million in crypto assets at the time of the attack.
How did North Korean hackers infiltrate Drift Protocol?
The attackers posed as a quantitative trading firm for six months, attending crypto conferences and building relationships with Drift contributors. They deposited over $1 million to appear legitimate, then compromised team members through malicious code repositories and a fake wallet app, gaining access to multisig signing authority.
Can affected Drift Protocol users recover their funds?
Recovery remains uncertain. Drift is working with law enforcement and forensic investigators including Mandiant. Most stolen funds were quickly bridged to Ethereum and converted, making recovery difficult. Blockchain analytics firms are tracking the fund flows, but DPRK actors have historically been effective at laundering stolen crypto through mixers and chain-hopping.








