Close Menu
Altcoinvest
    What's Hot

    50,640 People Affected After Hackers Hit Healthcare Firm, Stealing Personal, Financial and Medical Data

    April 18, 2026

    Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains

    April 18, 2026

    Ethereum Signals Major Reversal – $2,900 Target Back In Focus

    April 18, 2026
    Facebook X (Twitter) Instagram
    Altcoinvest
    • Bitcoin
    • Altcoins
    • Exchanges
    • Youtube
    • Crypto Wallets
    • Learn Crypto
    • bitcoinBitcoin(BTC)$75,824.00-2.06%
    • ethereumEthereum(ETH)$2,354.15-3.17%
    • tetherTether(USDT)$1.00-0.01%
    • rippleXRP(XRP)$1.43-3.40%
    • binancecoinBNB(BNB)$631.14-1.73%
    • usd-coinUSDC(USDC)$1.000.00%
    • solanaSolana(SOL)$86.22-3.33%
    • tronTRON(TRX)$0.3291760.56%
    • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.31%
    • dogecoinDogecoin(DOGE)$0.094948-5.38%
    Altcoinvest
    Home»Crypto Wallets»Drift Says $270M Crypto Hack Was a Six-Month North Korean Intelligence Operation
    Drift Says 0M Crypto Hack Was a Six-Month North Korean Intelligence Operation
    Crypto Wallets

    Drift Says $270M Crypto Hack Was a Six-Month North Korean Intelligence Operation

    April 7, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Drift Crypto Protocol has attributed a $270 million exploit executed on April 1, 2026 to a six-month intelligence operation conducted by UNC4736 – a North Korean state-affiliated threat group also tracked as Citrine Sleet or AppleJeus – in a detailed incident update published by the team on Sunday,

    making it the largest native Solana decentralized application exploit on record. Attackers posed as a quantitative trading firm, deposited more than $1 million of their own capital into an Ecosystem Vault, held working sessions with contributors across multiple countries, and waited nearly half a year before executing a durable nonce attack that drained protocol vaults in under a minute.


    The operation’s scope and duration distinguish it from prior DeFi exploits in ways that carry implications well beyond Drift’s immediate recovery.

    We suspect this is less a measure of Drift’s specific security posture and more a calibrated signal about the maturity of state-sponsored cryptocurrency theft operations – one that renders the standard DeFi security checklist, smart contract audits included, structurally inadequate against adversaries operating on intelligence timelines rather than opportunistic ones.

    I beg everyone in crypto to read this in full.

    I expected this to be another case of social engineering, likely some recruiter/job offer shit.

    I was very wrong.

    And the depth of the operation and personas makes me think they already have multiple other teams on lock.

    😳 https://t.co/8ZTEDwqs9Y

    — Tay 💖 (@tayvano_) April 5, 2026

    DISCOVER: Meme coin supercycle: Top performers this week

    UNC4736 Operation On Drift Crypto: Six-Month Timeline, Dual Intrusion Vectors, and the Durable Nonce Execution

    According to Drift crypto incident update, first contact occurred in fall 2025 at a major crypto conference, where the group presented themselves as a technically fluent quant trading firm seeking vault integration.

    The relationship followed entirely standard DeFi onboarding patterns – a Telegram group, sustained conversations about trading strategies, and substantive discussions around protocol architecture – none of which would have flagged as anomalous to contributors accustomed to institutional counterparties conducting extended due diligence.

    Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, deposited over $1 million in capital, and established a functioning operational presence inside the ecosystem.

    Drift crypto contributors met individuals associated with the group face to face at multiple major industry conferences across several countries through February and March 2026 – a detail that underscores a known DPRK operational pattern: the individuals appearing in person were not North Korean nationals but third-party intermediaries carrying fully constructed professional identities, employment histories, and social networks built to withstand due diligence review.

    pretty crazy if true

    tl:dr – hackers casually gained trust via irl conference meet, setup tg channel and became a customer, started building integrations over 6 months and then got one person with a testflight link to show off what they built https://t.co/LLW7yFBpNs

    — mert (@mert) April 5, 2026

    The technical intrusion appears to have proceeded through two vectors identified in Drift’s disclosure. The first involved a TestFlight application – Apple’s platform for distributing pre-release software that bypasses App Store security review – which the group presented as their proprietary wallet product.

    The second exploited a known vulnerability in VSCode and Cursor, two widely used code editors, where opening a file or folder was sufficient to silently execute arbitrary code; the security community had been flagging this vector since late 2025.

    Once contributor devices were compromised, attackers obtained the two multisig approvals required to pre-sign transactions using Solana’s durable nonce mechanism. Those transactions sat dormant for more than a week before activating on April 1, draining $270 million – including 41.72 million JLP tokens subsequently swapped through Jupiter, Raydium, Orca, and Meteora and bridged to Ethereum – in under sixty seconds.

    Attribution to UNC4736 is based on on-chain fund flows linking the attack to wallets associated with the October 2024 Radiant Capital exploit, as well as operational overlap with known DPRK-linked personas identified by forensic firm Mandiant, which Drift retained for investigation, and blockchain security firm SEALS 911, which assigned the connection medium-high confidence. UNC4736 operates under North Korea’s Reconnaissance General Bureau – the same directorate responsible for prior AppleJeus malware campaigns – and its playbook has progressively incorporated extended in-person social engineering as a precursor phase.

    We anticipate Mandiant’s full forensic report will surface additional infrastructure overlaps connecting this operation to prior Lazarus Group-adjacent campaigns beyond the Radiant Capital wallet cluster already identified.

    EXPLORE: Crypto breakout alerts this week

    next

    Disclaimer: Coinspeaker is committed to providing unbiased and transparent reporting. This article aims to deliver accurate and timely information but should not be taken as financial or investment advice. Since market conditions can change rapidly, we encourage you to verify information on your own and consult with a professional before making any decisions based on this content.

    Web3 News, Cybersecurity News

    Neil Mathew

    Neil is a professional cryptocurrency content writer with years of experience. He has written for various cryptocurrency websites to report on breaking news, and been hired by all sorts of cryptocurrency projects, to create content that would increase their exposure and attract more potential investors.

    Neil Mathew on LinkedIn


    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Ethereum Signals Major Reversal – $2,900 Target Back In Focus

    April 18, 2026

    Iran Oil Tanker Fees Still Dominated by USDt, No Signs of BTC Yet: BPI

    April 18, 2026

    Iran marks 100 days since crackdown with regime stability unchanged

    April 18, 2026

    Here’s When To Buy And When To Sell

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Tweets by InfoAltcoinvest

    Top Posts

    Ethereum Signals Major Reversal – $2,900 Target Back In Focus

    April 18, 2026

    Iran Oil Tanker Fees Still Dominated by USDt, No Signs of BTC Yet: BPI

    April 18, 2026

    Iran marks 100 days since crackdown with regime stability unchanged

    April 18, 2026

    Solana (SOL) Jumps 7% Daily, Bitcoin (BTC) Rebounds to $65K: Market Watch

    February 25, 2026

    30w raycus fiber marking machine with rotary 110110mm 2

    December 5, 2025

    CoinShares Withdraws Multiple US Crypto ETF Applications — Details

    November 29, 2025

    Custom Brass Coin – Fiber Laser – Omtech 50w Raycus

    March 5, 2026

    Altcoinvest is a leading platform dedicated to providing the latest news and insights on the dynamic world of cryptocurrencies.

    We're social. Connect with us:

    Facebook X (Twitter)
    Top Insights

    50,640 People Affected After Hackers Hit Healthcare Firm, Stealing Personal, Financial and Medical Data

    April 18, 2026

    Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains

    April 18, 2026

    Ethereum Signals Major Reversal – $2,900 Target Back In Focus

    April 18, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.


    Facebook X (Twitter)
    • Home
    • About us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    © 2026 altcoinvest.com

    Type above and press Enter to search. Press Esc to cancel.