Home International‘Six Months in the Making’: Drift Protocol Says $2...
International⭐ Featured

‘Six Months in the Making’: Drift Protocol Says $285,000,000+ Hack Involved North Korean-Backed Impostors at Multiple Crypto Conferences

The recent $285 million hack on the Solana-based DeFi platform Drift Protocol wasn’t any run-of-the-mill exploit. Drift Protocol says in a new incident update that the April 1st attack was the result of six months of careful manipulation from North Korean-backed impostors. “In or about Fall 2025, Drift contributors were approached by a group of […] The post ‘Six Months in the Making’: Drift Protocol Says $285,000,000+ Hack Involved North Korean-Backed Impostors at Multiple Crypto Conferences appeared first on The Daily Hodl .

7 April 2026 at 08:03 am
1 views
‘Six Months in the Making’: Drift Protocol Says $285,000,000+ Hack Involved North Korean-Backed Impostors at Multiple Crypto Conferences

The recent $285 million hack on the Solana-based DeFi platform Drift Protocol was not a typical exploit. Drift Protocol has revealed in a new incident update that the April 1st attack was the result of six months of meticulous manipulation by North Korean-backed impostors. The group had approached Drift contributors in the fall of 2025 at a major crypto conference, posing as a quantitative trading firm interested in integrating with the protocol.

The impostors were well-prepared, with technical expertise, verifiable professional backgrounds, and knowledge of how Drift operated. They established a Telegram group during their initial meeting and proceeded to engage in months of detailed discussions about trading strategies and potential vault integrations. These interactions were consistent with the standard process by which trading firms interact with and onboard to Drift.

Over the following six months, the impostors deliberately sought out and engaged specific Drift contributors at multiple major industry conferences in various countries. They onboarded an Ecosystem Vault on Drift in December and January, participating in numerous working sessions and depositing over $1 million of their own capital. Integration conversations continued through February and March 2026, with the impostors meeting Drift contributors face-to-face at multiple conferences.

By this point, the relationship between the impostors and Drift contributors had lasted nearly six months. The individuals involved were not strangers; they were people Drift contributors had worked with and met in person. Throughout the process, the impostors shared links to projects, tools, and apps they claimed to be developing, which was standard practice for trading firms.

Drift Protocol's investigation has concluded with "medium-high confidence" that the attack was orchestrated by North Korean-backed actors. The sophisticated approach used by the impostors highlights the growing sophistication of cyber threats in the crypto space and the need for increased vigilance and security measures among platforms and participants.

This incident underscores the importance of due diligence and verification processes in the crypto industry, particularly when dealing with new partners or entities. As the space continues to grow, it is crucial for platforms to implement robust security protocols and stay vigilant against such targeted attacks. The Drift Protocol hack serves as a stark reminder of the potential risks involved in the rapidly evolving world of decentralized finance.

📰 Related News
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 is now live, featuring native support for Google's Gemma 4 models and improved local inference performance for Windows, macOS, and Linux.
14 Apr
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Below are the most-read DIGITIMES Asia stories from the week of April 6-April 13, 2026:
14 Apr
cutile-stencil 0.2.0
cutile-stencil 0.2.0
An xDSL-based stencil compiler that generates optimized GPU kernels via NVIDIA cuTile
14 Apr
merlin-llm added to PyPI
merlin-llm added to PyPI
Merlin — a fast local LLM for agentic coding on Apple Silicon
14 Apr
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Craft and compose videos programmatically in PHP with an elegant fluent API - b7s/fluentcut
14 Apr
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Justin Sun has accused Trump-affiliated World Liberty Financial of misconduct and a general lack of transparency.
14 Apr
nvidia-nat-weave 1.7.0a20260413
nvidia-nat-weave 1.7.0a20260413
Subpackage for Weave integration in NeMo Agent Toolkit
14 Apr
nvidia-nat-s3 1.7.0a20260413
nvidia-nat-s3 1.7.0a20260413
Subpackage for S3-compatible integration in NeMo Agent Toolkit
14 Apr
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Six years. That is how much time separates retirees from a Social Security system that, by its own projections, runs out of money. If you are 56 years old...
14 Apr
cane-gpu-perf added to PyPI
cane-gpu-perf added to PyPI
GPU inference benchmarking with opinionated diagnostics
13 Apr