logo

Drift $280M crypto theft linked to 6-month in-person operation

ID: d5e84e22-2e7a-50e0-81f0-4a7834020041

STIX ID: report--d5e84e22-2e7a-50e0-81f0-4a7834020041

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Drift Protocol experienced a sophisticated, multi-month targeted compromise that resulted in the theft of over $280M; investigators (Drift, Elliptic, TRM Labs) attribute the operation to North Korean-linked UNC4736, which used in-person social engineering at crypto conferences, Telegram communications, a malicious code repository (possible VSCode/Cursor vulnerability), and a malicious TestFlight wallet app to compromise contributors and hijack administrative multisig controls. The protocol is currently frozen and attacker wallets have been flagged across exchanges and bridges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.