North Korea Spent 6 Months Infiltrating Drift Protocol Only to Drain $285M in 12 Mins
ID: ef57f8f0-fc86-56f2-b174-703b816650e7
STIX ID: report--ef57f8f0-fc86-56f2-b174-703b816650e7
Feed Name: The Cyber Express
A sophisticated, six-month operation attributed to DPRK-linked UNC4736 compromised Drift Protocol (a Solana-based perpetual futures exchange) on April 1, 2026, stealing roughly $285M. Attackers posed as a trading firm, used wash trading to create a fake token (CVT) that fooled price oracles, compromised contributor devices and multisig signers via social engineering and a malicious TestFlight app/VSCode vulnerability, and exploited Solana durable nonces to pre-sign and later execute admin transactions that enabled a rapid drain and cross-chain laundering; Drift has frozen protocol functions and is coordinating recovery efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
