Drift Protocol confirms $285 million hack was a North Korean operation

Drift Protocol $285 million hack linked to North Korean state-sponsored hackers

Key takeaways

  • North Korean state-sponsored hackers stole approximately $285 million from Drift Protocol, Solana’s largest decentralized perpetual futures exchange, on April 1, 2026.
  • The theft was the result of a six-month social engineering campaign that began at crypto conferences in fall 2025, using fake quant traders and non-Korean intermediaries to gain trust.
  • Blockchain analytics firms Elliptic and TRM Labs attributed the attack to DPRK group UNC4736, marking at least the eighteenth North Korean crypto operation tracked in 2026.
  • Drift’s total value locked collapsed from $550 million to under $250 million. No concrete fund recovery timeline has been announced.

Published: April 6, 2026 12:00 UTC

Drift Protocol, the largest decentralized perpetual futures exchange on Solana, confirmed on April 5 that the $285 million drained from its vaults on April 1 was the result of a six-month intelligence operation run by suspected North Korean state-sponsored hackers. The disclosure makes this the second-largest hack in Solana’s history and one of the most sophisticated social engineering attacks ever documented in decentralized finance.

A decentralized perpetual futures exchange is a platform that lets traders bet on the future price of crypto assets without expiry dates, operating through smart contracts instead of a centralized company.

How the six-month operation unfolded

The campaign began in fall 2025 when individuals posing as a quantitative trading firm approached Drift contributors at a major crypto conference. Over the following months, these operatives met Drift team members face-to-face at industry events across six countries, building relationships through substantive conversations about trading strategies.

To establish credibility, the attackers deposited more than $1 million of their own funds into Drift. They also deployed third-party intermediaries who were not North Korean nationals for in-person meetings, making detection harder. A Telegram group was set up at the first meeting and maintained throughout the campaign.

Between December 2025 and March 2026, the operatives shared malicious code through two infection vectors. The first was a weaponized Microsoft Visual Studio Code project with a modified “tasks.json” file that executed harmful code automatically when opened. The second was a fake wallet application distributed through Apple’s TestFlight beta testing platform, which a Drift contributor was persuaded to install.

Cybersecurity threat in decentralized finance Drift Protocol hack

What was stolen and how

On April 1, the attackers executed the theft by compromising administrator private keys, according to blockchain security firm PeckShield. The attacker’s wallet had been created eight days earlier with a test transfer, indicating careful preparation.

The stolen assets spanned more than 15 token types, including 41.7 million JLP tokens worth approximately $155 million, along with USDC, SOL, cbBTC, wBTC, and various liquid staking tokens. The attacker rapidly swapped stolen tokens into USDC via Solana decentralized exchanges, then bridged the funds to Ethereum.

Drift’s total value locked dropped from $550 million to under $250 million. Users were temporarily unable to deposit or withdraw funds.

North Korea attribution and the bigger pattern

Blockchain analytics firm Elliptic identified on-chain behavior, laundering methodologies, and network-level indicators consistent with previous DPRK-attributed operations. TRM Labs reached a similar conclusion, tracing fund flows back to wallets linked to the 2024 Radiant Capital hack ($53 million) and finding operational persona overlaps with known North Korean activity.

The threat actor has been attributed with medium confidence to UNC4736, a group also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces. This same cluster was linked to the 2023 3CX supply chain compromise.

If confirmed, the Drift exploit would be at least the eighteenth DPRK crypto operation tracked in 2026, pushing the year’s total past $300 million. North Korean hackers stole an estimated $2 billion in crypto during 2025, representing roughly 60% of all global digital asset theft that year, and carried out the record-setting $1.5 billion Bybit hack.

What comes next

Drift said it is working with law enforcement and forensic partners to investigate, though no concrete recovery timeline has been provided. The protocol was founded in 2021 by Cindy Leow and David Lu.

The attack has renewed scrutiny of how DeFi protocols manage multisig security and contributor vetting. Unlike typical smart contract exploits, this breach succeeded through human compromise rather than code vulnerability, a pattern that has become North Korea’s signature approach to crypto theft.

The U.S. government has publicly linked North Korean crypto theft to weapons program funding. As DeFi protocols manage larger sums with relatively small teams, the gap between asset value and operational security continues to widen.

Frequently asked questions

What happened to Drift Protocol?

On April 1, 2026, approximately $285 million was stolen from Drift Protocol, Solana’s largest decentralized perpetual futures exchange. The attack was carried out by suspected North Korean state-sponsored hackers who spent six months infiltrating the team through social engineering before compromising administrator private keys.

Who was behind the Drift Protocol hack?

Blockchain analytics firms Elliptic and TRM Labs attributed the attack to UNC4736, a North Korean state-sponsored hacking group also known as AppleJeus and Citrine Sleet. The group is linked to previous crypto hacks including the 2024 Radiant Capital exploit and the 2023 3CX supply chain breach.

Can Drift Protocol users recover their stolen funds?

Drift has stated it is working with law enforcement and forensic partners but has not announced a recovery timeline. The stolen tokens were quickly swapped to USDC and bridged to Ethereum, making recovery difficult. Drift’s total value locked dropped from $550 million to under $250 million after the attack.

Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *