Articles
Crypto Market Analysis

Drift Protocol $280M exploit took 'months of deliberate preparation'

User Image

Bởi Ẩn danh

Được tạo April 05, 2026|2 phút đọc
Main Image

Drift Protocol said, with “medium-high confidence,” that the recent attack was carried out by the same actors responsible for the $58 million Radiant Capital hack in October 2024.

Drift Protocol, a decentralized cryptocurrency exchange (DEX), says the recent exploit against the platform was a six-month-long, highly coordinated attack.

“The preliminary investigation shows that Drift experienced a structured intelligence operation requiring organizational backing, significant resources, and months of deliberate preparation,” Drift said in an X post on Saturday.

The decentralized exchange was exploited on Wednesday, with external estimates putting losses at around $280 million.

According to Drift, the attack plan can be traced back to around October 2025, when malicious actors posing as a quantitative trading firm first approached Drift contributors at a “major crypto conference,” claiming to be interested in integrating with the protocol.

The group continued to engage contributors in person at multiple industry events over the following six months. “It is now understood that this appears to be a targeted approach, where individuals from this group continued to deliberately seek out and engage specific Drift contributors,” Drift said.

“They were technically fluent, had verifiable professional backgrounds, and were familiar with how Drift operated,” Drift said.

After gaining trust and access to Drift Protocol over six months, they used shared malicious links and tools to compromise contributors’ devices, execute the exploit, and then wiped their presence immediately after the attack.

The incident serves as a reminder for crypto industry participants to remain cautious and skeptical, even during in-person interactions, as crypto conferences can be prime targets for sophisticated threat actors.

Drift said, with “medium-high confidence,” that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.

In December 2024, Radiant Capital said the exploit was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor. 

“This ZIP file, when shared for feedback among other developers, ultimately delivered malware that facilitated the subsequent intrusion,” Radiant Capital said.

Drift said it is “important to note” that the individuals who appeared in person “were not North Korean nationals.”

Related: Naoris launches post-quantum blockchain as quantum security risks gain attention

“DPRK threat actors operating at this level are known to deploy third-party intermediaries to conduct face-to-face relationship-building,” Drift said.

Drift said that it is working with law enforcement and others in the crypto industry to “build a complete picture of what happened during the April 1st attack.”

Magazine: Bitcoin 85% crashes ‘done,’ CLARITY Act speculation mounts: Hodler’s Digest, Mar. 29 – April 4

Source: CoinTelegraph


Các bài viết khác được xuất bản gần đây

Crypto's Clarity Act is a Schrödinger's cat in life-death limbo as U.S. Senate returns
Crypto's Clarity Act is a Schrödinger's cat in life-death limbo as U.S. Senate returns

Crypto Market Analysis

The crypto industry eagerly awaits a September 15 vote, though it might not happen. Or maybe it will...

Circle's $400M Tazapay deal buys emerging market links that take ‘years to build’
Circle's $400M Tazapay deal buys emerging market links that take ‘years to build’

Crypto Market Analysis

Stablecoins' “next battleground is in emerging markets,” one expert said, as Circle looks to exp...

Fed rate hike is about Wall Street, not inflation, says economist
Fed rate hike is about Wall Street, not inflation, says economist

Crypto Market Analysis

Goldman Sachs late Friday became the last of the major banks to retract its forecast of no rate hike...

Quantum-proof blockchain: why math, not machines, holds the key
Quantum-proof blockchain: why math, not machines, holds the key

Blockchain

lockchains don’t need quantum computers to be quantum-safe, argues Optimum co-founder and MIT prof...

Revolut says customer data exposed through fake government email
Revolut says customer data exposed through fake government email

Crypto Market Analysis

Passports, selfies and financial transaction histories of some customers were revealed to a fraudste...

Anthropic chief urges slowdown in AI development to safer pace
Anthropic chief urges slowdown in AI development to safer pace

Crypto Market Analysis

OpenAI CEO Sam Altman agrees with safety concerns regarding AI development, says no initial share sa...