Cointime

Download App
iOS & Android

Drift Protocol says $280M exploit took 'months of deliberate preparation'

Drift Protocol, the decentralized exchange (DEX) that lost an estimated $280 million in an exploit last week, claims the loss was the result of a six-month, highly coordinated attack.

“The preliminary investigation shows that Drift experienced a structured intelligence operation requiring organizational backing, significant resources, and months of deliberate preparation,” Drift said in an X post on Saturday.

Attack began at a “major crypto conference”

According to Drift, the attack can be traced back to around October 2025, when malicious actors posing as a quantitative trading firm first approached Drift contributors at a “major crypto conference,” claiming to be interested in integrating with the protocol.

  Source: Drift Protocol


The group continued to engage contributors in person at multiple industry events over a six-month period. “It is now understood that this appears to be a targeted approach, where individuals from this group continued to deliberately seek out and engage specific Drift contributors,” Drift said.

“They were technically fluent, had verifiable professional backgrounds, and were familiar with how Drift operated,” Drift said.

After gaining trust and access to Drift Protocol over six months, they used shared malicious links and tools to compromise contributors’ devices, execute the exploit, and then wiped their presence immediately after the attack.

The incident serves as a reminder for crypto industry participants to remain cautious and skeptical, even during in-person interactions, as crypto conferences can be prime targets for sophisticated threat actors.

Drift flags a high probability of a Radiant Capital hack link

Drift said, with “medium-high confidence,” that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.

In December 2024, Radiant Capital said the exploit was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor. 

  Source: Dith


“This ZIP file, when shared for feedback among other developers, ultimately delivered malware that facilitated the subsequent intrusion,” Radiant Capital said.

Drift said that the individuals who appeared in person “were not North Korean nationals.”

“DPRK threat actors operating at this level are known to deploy third-party intermediaries to conduct face-to-face relationship-building,” Drift said.

Drift said that it is working with law enforcement and others in the crypto industry to “build a complete picture of what happened during the April 1st attack.”

Comments

All Comments

Recommended for you

  • BTC Surpasses $73,000

    Market data shows that BTC has surpassed $73,000, currently priced at $73,010, with a 24-hour increase of 3.3%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Iranian Armed Forces Declare Readiness to Fire at Any Time

    On April 10, a spokesperson for the Central Headquarters of the Iranian Armed Forces, Khatam al-Anbiya, stated that due to the repeated breaches of trust by the United States and Israel, the Iranian Armed Forces remain on full alert and are ready to fire at any time. (Xinhua News Agency)

  • U.S. Core CPI in March Increases 2.6% Year-on-Year, Estimated at 2.7%

    On April 10, it was reported that the U.S. core consumer price index (CPI) increased by 2.6% year-on-year in March, slightly below the estimated 2.7%, and up from the previous value of 2.5%. Month-on-month, it rose by 0.2%, compared to an estimate of 0.3%.

  • US March CPI Increases 3.3% Year-on-Year, Highest Since May 2024

    On April 10, it was reported that the US Consumer Price Index (CPI) for March increased by 3.3% year-on-year, marking the highest level since May 2024. The forecast was 3.4%, while the previous value was 2.4%. The seasonally adjusted CPI for March rose by 0.9% month-on-month, matching expectations of 0.9%, compared to the previous value of 0.30%.

  • Fed's Daly: Likelihood of Rate Hike Lower than Rate Cut or Holding Steady

    Fed's Daly stated that if the Iran conflict is resolved quickly and oil prices decline, a rate cut is 'not out of the question.' If inflation remains above expectations for an extended period, we will remain cautious until we are confident that the inflation issue has been addressed. We had work to do on inflation before the oil price shock; now, this work simply requires more time. The likelihood of a rate hike is considered lower than that of a rate cut or maintaining the current rate.

  • BTC Surpasses $72,000

    Market data shows that BTC has surpassed $72,000, currently priced at $72,004.75, with a 24-hour increase of 1%. The market is highly volatile, so please ensure proper risk management.

  • Circle stock sinks 10% amid analyst downgrade, Drift Protocol probe

    The stablecoin issuer faces pressure after a stock downgrade and Drift Protocol exploit fallout, raising concerns over USDC exposure, crypto regulation and market risk.

  • Hong Kong grants first stablecoin licences to Anchorpoint and HSBC

    Hong Kong has issued its first stablecoin licences, approving Anchorpoint Financial and HSBC’s Hong Kong banking arm under the HKMA’s new regime.

  • HSBC Plans to Launch Hong Kong Dollar-Pegged Stablecoin in Second Half of 2026

    On April 10, HSBC announced its support for the Hong Kong Monetary Authority's issuance of stablecoin licenses. The bank plans to launch a Hong Kong dollar-pegged stablecoin in the second half of 2026.

  • HSBC and Standard Chartered Obtain Stablecoin Licenses in Hong Kong

    On April 10, the Hong Kong Monetary Authority announced that the Financial Commissioner has granted stablecoin issuer licenses to two institutions—Anchor Financial Technology Limited (a company formed by Standard Chartered Bank (Hong Kong), Hong Kong Telecom, and Anxin Group) and HSBC. This marks a new phase in the implementation of Hong Kong's stablecoin regulatory framework.