Home TechnologyNorth Korean Hackers Pose as Trading Firm to Steal...
Technology⭐ Featured

North Korean Hackers Pose as Trading Firm to Steal $285M from Drift

North Korean hackers (UNC4736) posed as a trading firm for six months to infiltrate Drift Protocol, using social engineering tactics to steal $285M without suspicion.

6 April 2026 at 07:04 pm
1 views
North Korean Hackers Pose as Trading Firm to Steal $285M from Drift

North Korean Hackers Pose as Trading Firm to Steal $285M from Drift

In a sophisticated cyberattack that highlights the growing risks of social engineering in the cryptocurrency space, North Korean hackers linked to the UNC4736 group successfully infiltrated Drift Protocol, a decentralized finance (DeFi) platform, and stole approximately $285 million. The attackers posed as a legitimate trading firm for six months, meticulously crafting their strategy to gain access and execute the heist without raising immediate suspicion.

The operation began when the hackers created a convincing front of a reputable trading firm, complete with professional-looking websites, social media profiles, and even a team of actors to represent the company's executives. They targeted key individuals within the Drift Protocol community, including developers, investors, and influencers, to build credibility and establish trust. Through a combination of phishing emails, fake social media accounts, and even forged partnership agreements, the hackers were able to infiltrate the platform's inner circles.

One of the critical components of the attack was the hackers' ability to exploit the trust and curiosity of Drift Protocol's community. They engaged in discussions on forums and social media, sharing insights and participating in debates about the future of DeFi. This prolonged engagement allowed them to identify vulnerabilities in the platform's security measures and understand the inner workings of its governance structure.

Once they had established a foothold, the hackers began to execute their plan. They leveraged their newfound access to manipulate the platform's smart contracts, enabling them to drain funds from the platform's treasury. The theft was carried out in stages, with the hackers carefully monitoring the platform's activity to ensure that their actions did not trigger any alarms.

The attack was not immediately detected, as the hackers had meticulously planned their exit strategy. They transferred the stolen funds to multiple cryptocurrency addresses, making it difficult for authorities to trace the money. However, the theft was eventually discovered when Drift Protocol's team noticed unusual activity in the platform's transaction logs.

The incident has raised serious concerns about the security of DeFi platforms and the risks associated with social engineering attacks. Drift Protocol has since announced that it is working with law enforcement agencies to investigate the theft and recover the stolen funds. The platform has also implemented additional security measures to prevent future attacks, including enhanced due diligence processes for new community members and improved monitoring of smart contract activity.

This attack underscores the need for greater vigilance and robust security practices within the DeFi ecosystem. As the industry continues to grow, so too do the risks of sophisticated cyberattacks. Platforms must prioritize security and invest in advanced threat detection systems to protect themselves and their users from similar threats.

In response to the attack, the international community has called for increased cooperation between governments, law enforcement agencies, and the cryptocurrency industry to combat such threats. The UNC4736 group, known for its involvement in previous high-profile attacks, has once again demonstrated the potential for significant financial damage through cybercrime.

As the investigation into the Drift Protocol heist continues, the cryptocurrency community remains on high alert. The success of this attack serves as a stark reminder of the challenges faced by DeFi platforms and the importance of prioritizing security in an ever-evolving digital landscape.

šŸ“° Related News
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras Founder Palak Shah’s ₹40 Lakh Billboard Mistake Became a Masterclass in Startup Marketing
Ekaya Banaras founder Palak Shah recently opened up about one of the most expensive mistakes she made while building her luxury textile brand. During the early years of the company, Shah rented a premium billboard near Delhi’s DLF Emporio to increase brand visibility. However, after forgetting to cancel the campaign, the hoarding reportedly continued running for months — resulting in losses of nearly ₹40 lakh. The incident has now become a viral example of how small operational oversights can turn into costly business lessons for startups and entrepreneurs.
28 May
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Betting On AI: Jensen Huang And NVIDIA’s Rise To The Top
Before AI was inevitable, it was a gamble—and Jensen Huang went all in.
14 Apr
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1 bring confidential computing to bare metal and AI workloads
Red Hat is excited to announce the release of Red Hat OpenShift sandboxed containers 1.12 and Red Hat build of Trustee 1.1, marking a major leap forward in our confidential computing journey. These releases graduate confidential containers on bare metal from …
14 Apr
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
Large AI firms hoovering maximum funding, not enough for smaller startups: Y Combinator’s Ankit Gupta
YC Startup School: India’s talent pool across colleges and universities are key for building next-gen startups, which is what YC is looking to tap into. It wants to target entrepreneurs building for global markets, focussed on fintech, consumer, B2B, and ecom…
14 Apr
TSMC likely to book fourth straight quarter of record profit onĀ insatiable AI demand
TSMC likely to book fourth straight quarter of record profit onĀ insatiable AI demand
TSMC-RESULTS/ (PREVIEW, PIX):PREVIEW-TSMC likely to book fourth straight quarter of record profit onĀ insatiable AI demand
14 Apr
TSMC likely to book fourth straight quarter of record profit onĀ insatiable AI demand
TSMC likely to book fourth straight quarter of record profit onĀ insatiable AI demand
Any profit result ā€Œabove T$505.7 billion would mark the company's highest-ever quarterly net income ​and its ninth consecutive quarter of profit growth
14 Apr
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
TSMC likely to book fourth straight quarter of record profit on insatiable AI demand
On Thursday, ​TSMC is expected to report a net profit of $17.1 billion for the quarter, according to an LSEG SmartEstimate compiled from 19 analysts. The war in the Middle East threatens to disrupt the supply of production materials for semiconductors such as…
14 Apr
If we can’t kick the habit, how do we manage AI’s energy needs?
If we can’t kick the habit, how do we manage AI’s energy needs?
One can only hope that OpenAI’s Sam Altman was joking when he sought to justify the immense energy consumption of artificial intelligence
14 Apr
What caused Nvidia Blackwell GPU prices to spike? #tech
What caused Nvidia Blackwell GPU prices to spike? #tech
Blackwell GPU hourly ā€œrentā€ surges on agentic AI demand A compute pricing index tracking hourly costs for Nvidia Blackwell GPUs shows a sharp climb: hourly rental hit $4.08 , up 48% from $2.75 just two months earlier. The reported driver is rising demand tied…
14 Apr
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic Releases Claude Mythos Preview with Cybersecurity Capabilities but Withholds Public Access
Anthropic has introduced Claude Mythos Preview, its most advanced AI model, improving significantly in reasoning, coding, and cybersecurity. Unlike previous releases, it will not be publicly available. Access is limited to a consortium of tech companies throu…
14 Apr