Cointime

Download App
iOS & Android

Crypto attorney says Drift incident may qualify as 'civil negligence'

The hack of the Solana-based decentralized finance (DeFi) platform Drift Protocol could have been prevented if standard operational security procedures were followed by the Drift team, and may constitute “civil negligence,” according to attorney Ariel Givner.

“In plain terms, civil negligence means they failed their basic duty to protect the money they were managing,” Givner said in response to the post-mortem update provided by the Drift team and how it handled Wednesday’s $280 million exploit.

The Drift team failed to follow “basic” security procedures, including keeping signing keys on separate, “air-gapped” systems that are never used for developer work, and conducting due diligence on blockchain developers met through industry conferences.

  Source: Ariel Givner


“Every serious project knows this. Drift didn’t follow it,” she said, adding, “They knew crypto is full of hackers, especially North Korean state teams.” Givner continued: 

“Yet their team spent months chatting on Telegram, meeting strangers at conferences, opening sketchy code repos, and downloading fake apps on devices tied to multisignature controls.”

Advertisements for class action lawsuits against Drift Protocol are already circulating, she said. Cointelegraph reached out to the Drift Team but did not receive a response by the time of publication.

  Source: Ariel Givner


The incident is a reminder that social engineering and project infiltration by malicious actors are major attack vectors for cryptocurrency developers that could drain user funds and permanently erode customer trust in compromised platforms.

Drift Protocol says attack took “months” of planning

The Drift Protocol team published an update on Saturday outlining how the exploit occurred and claimed that the attackers planned the attack for six months before execution.

Threat actors first approached the Drift team at a “major” crypto industry conference in October 2025, expressing interest in protocol integrations and collaboration.

The malicious actors continued to build rapport with the Drift development team in the ensuing six months, and once enough trust was built, they began sending the Drift team malicious links and embedding malware that compromised developer machines.These individuals, who are suspected of working for North Korea state-affiliated hackers and physically approached the Drift developers, were not North Korean nationals, according to the Drift team.

Drift said, with “medium-high confidence,” that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.

In December 2024, Radiant Capital said the exploit was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor. 

Comments

All Comments

Recommended for you

  • Trump Evacuated from White House Correspondents' Dinner Due to Security Incident

    On April 26, local time April 25, U.S. President Trump was urgently evacuated from the White House Correspondents' Dinner due to a security incident. (CCTV News)

  • Shooting Incident at White House Correspondents' Dinner; Gunman Dead

    On April 26, local time on April 25, a shooting incident occurred in the hall of the White House Correspondents' Dinner, and the gunman is now deceased. (CCTV News)

  • Trump States He Will Not Allow Banks to Undermine Cryptocurrency Market Legislation

    On April 26, CoinDesk reported, citing attendees at a Trump cryptocurrency event, that Trump stated he would not allow banks to undermine cryptocurrency market legislation.

  • Iranian Officials to Depart Pakistan Without Meeting U.S. Representatives

    On April 25, according to a reporter from the New York Post: The Iranian delegation is set to leave Islamabad, the capital of Pakistan, and has consistently emphasized that they did not meet with U.S. officials during their brief visit.

  • Foreign Media: Second Round of Iran-U.S. Talks Scheduled for April 27

    On April 25, according to New Delhi Television: The second round of talks between Iran and the United States is scheduled to take place on April 27.

  • Iranian Lawmaker: Comprehensive Plan for Managing the Strait of Hormuz Formed

    On April 25, according to a report by Iran's Mehr News Agency, Iranian Islamic Parliament member Behnam Saidi stated that Iran has developed a comprehensive plan for managing the Strait of Hormuz. In an interview with Mehr News Agency, Saidi mentioned that an important aspect of this plan is the exclusive recognition of the name 'Persian Gulf' in all correspondence and commercial documents, rejecting any other names. Vessels and ships navigating in the region must obtain permission from Iran. Sovereignty over the Strait of Hormuz will be entirely under Iran's control. He also stated that vessels identified as hostile by the Supreme National Security Council or the General Staff of the Armed Forces of Iran are not allowed to pass through the Strait of Hormuz, and Israeli vessels are absolutely prohibited from entering the area. Ships passing through the region must pay relevant fees concerning safety, environmental protection, shipping management, and licensing, with priority given to payments in rials.

  • DeepSeek Plans to Raise $1.8 Billion with a Valuation of Approximately $20 Billion

    Sources reveal that the main reason for DeepSeek's current fundraising effort is the significant recent talent loss. Several core researchers have left the company to join ByteDance, Tencent, Xiaomi, and autonomous driving company Yuanrong Qihang. Meanwhile, competitors Zhiyu Technology and MiniMax have listed on the Hong Kong Stock Exchange, and the company Dark Side of the Moon has completed three rounds of financing in the first three months of this year, with a valuation more than quadrupling since the end of last year.

  • Iran Warns U.S. Against Continuing Piracy Actions

    On April 25, according to CCTV International News, Iran's Khatam al-Anbia Central Command issued a statement today warning that if U.S. forces continue to implement 'blockades, maritime interceptions, and piracy actions' in the region, they will face a strong counterattack from the Iranian armed forces. The statement emphasized that the U.S. should recognize that Iran's military capabilities and preparedness in safeguarding national sovereignty, territorial integrity, and national interests are stronger than ever, as demonstrated in previous conflicts. The statement also noted that Iran will continue to monitor enemy actions and movements and maintain control over the Strait of Hormuz. Should the enemy take further actions, Iran will respond with even harsher strikes.

  • Sources: Iran's Stance is Tougher than in First Round of Negotiations

    On April 25, official sources from Pakistan stated that Iran has adopted a tougher position compared to the first round of negotiations, emphasizing that any plan to end the war must be implemented according to Iran's conditions, rather than those proposed by U.S. President Trump. (Xinhua News Agency)

  • Iran Open to Negotiations with the U.S. but Will Not Abandon Uranium Enrichment

    On April 25, the Wall Street Journal reported that a senior Iranian diplomat stated Iran is open to negotiations with the United States but will not abandon its uranium enrichment activities. Iran's ambassador to India, Mohammad Fathali, posted on social media on Saturday, saying, 'Negotiations can yield appropriate results only when our opponents recognize our country's right to peacefully utilize nuclear energy.' The report indicates that the U.S. is currently seeking to have Iran suspend its uranium enrichment program for up to 20 years.