logo

Drift loses $280 million North Korean hackers seize Security Council powers

ID: 3864f355-ba4f-52ef-a07b-da2c49ed5895

STIX ID: report--3864f355-ba4f-52ef-a07b-da2c49ed5895

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-04-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Drift Protocol suffered a sophisticated exploit in which attackers obtained 2/5 multisig approvals, used durable nonce accounts and pre-signed transactions to time a takeover of Security Council admin powers, introduced a malicious asset, removed withdrawal limits, and drained approximately $280M–$285M; blockchain firms (Elliptic, TRM Labs) attributed the activity to North Korean-aligned actors based on on-chain indicators such as Tornado Cash usage, CarbonVote timing, cross-chain bridging, and rapid laundering, and the platform is working with security firms and law enforcement while freezing protocol activity and investigating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.