Cointime

Download App
iOS & Android

Crypto attorney says Drift incident may qualify as 'civil negligence'

The hack of the Solana-based decentralized finance (DeFi) platform Drift Protocol could have been prevented if standard operational security procedures were followed by the Drift team, and may constitute “civil negligence,” according to attorney Ariel Givner.

“In plain terms, civil negligence means they failed their basic duty to protect the money they were managing,” Givner said in response to the post-mortem update provided by the Drift team and how it handled Wednesday’s $280 million exploit.

The Drift team failed to follow “basic” security procedures, including keeping signing keys on separate, “air-gapped” systems that are never used for developer work, and conducting due diligence on blockchain developers met through industry conferences.

  Source: Ariel Givner


“Every serious project knows this. Drift didn’t follow it,” she said, adding, “They knew crypto is full of hackers, especially North Korean state teams.” Givner continued: 

“Yet their team spent months chatting on Telegram, meeting strangers at conferences, opening sketchy code repos, and downloading fake apps on devices tied to multisignature controls.”

Advertisements for class action lawsuits against Drift Protocol are already circulating, she said. Cointelegraph reached out to the Drift Team but did not receive a response by the time of publication.

  Source: Ariel Givner


The incident is a reminder that social engineering and project infiltration by malicious actors are major attack vectors for cryptocurrency developers that could drain user funds and permanently erode customer trust in compromised platforms.

Drift Protocol says attack took “months” of planning

The Drift Protocol team published an update on Saturday outlining how the exploit occurred and claimed that the attackers planned the attack for six months before execution.

Threat actors first approached the Drift team at a “major” crypto industry conference in October 2025, expressing interest in protocol integrations and collaboration.

The malicious actors continued to build rapport with the Drift development team in the ensuing six months, and once enough trust was built, they began sending the Drift team malicious links and embedding malware that compromised developer machines.These individuals, who are suspected of working for North Korea state-affiliated hackers and physically approached the Drift developers, were not North Korean nationals, according to the Drift team.

Drift said, with “medium-high confidence,” that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.

In December 2024, Radiant Capital said the exploit was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor. 

Comments

All Comments

Recommended for you

  • BTC Surpasses $75,000

    Market data shows that BTC has surpassed $75,000, currently priced at $75,306.4, with a 24-hour increase of 0.23%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Trump: Lebanon and Israel Agree to Ceasefire

    On April 16, U.S. President Trump stated, "I just had a very pleasant conversation with the esteemed President of Lebanon and Prime Minister Netanyahu of Israel. The two leaders have agreed to officially initiate a 10-day ceasefire at 5 PM Eastern Time in order to achieve peace between their two nations. On Tuesday, representatives from both countries attended the first meeting in 34 years alongside our great Secretary of State Rubio in Washington, D.C. I have instructed Vice President Vance, Secretary of State Rubio, and Chairman of the Joint Chiefs of Staff General Cain to work together with Israel and Lebanon to achieve lasting peace. It is my great honor to resolve 9 global conflicts, and this will be the 10th, so let’s push forward and complete this task!"

  • Iranian Armed Forces: Iranian Military Fully Prepared for Defense

    On April 16, local time, Pakistan Army Chief Munir reported to Abdollahi, the commander of Iran's Khatam al-Anbiya Central Command, on the measures taken by Pakistan to end the conflict, emphasizing that these efforts would continue. Abdollahi stated, "If the enemy harbors malicious intent, the Iranian military is fully prepared for defense." (CCTV)

  • U.S. Government Transfers 8.2 BTC to Coinbase Prime

    On April 16, according to Arkham monitoring, the U.S. government (funds seized from Bitfinex hackers) has just deposited 8.2 BTC (approximately $606,000) into Coinbase Prime.

  • Iran Reveals Details of Downing US C-130: Intelligence Coordination and Civil-Military Collaboration

    On April 16, according to CCTV, Iranian Army Chief Hatami disclosed for the first time details of an ambush operation against US military forces in southern Isfahan province during a speech on the same day. Hatami stated that the Iranian intelligence department had made thorough preparations in advance, involving the military, Revolutionary Guards, police, militia, and local citizens, to create a 'surrounding situation against the enemy.' In the ambush operation, Iran's initial firepower successfully shot down a C-130 transport aircraft. According to a statement released by the Iranian Law Enforcement Command on April 5, a police special forces unit shot down a US C-130 transport aircraft in the southern region of Isfahan.

  • Democrats on Senate Banking Committee Call for Delay of Walsh Hearing

    On April 16, Democratic members of the U.S. Senate Banking Committee stated that the hearing for Federal Reserve Chairman nominee Kevin Walsh should be postponed.

  • Anthropic Releases Latest Model OPUS 4.7

    On April 16, Anthropic released its latest model, Claude OPUS 4.7. The capabilities of OPUS 4.7 are not as comprehensive as those of the Mythos preview version. The pricing for OPUS 4.7 remains unchanged from OPUS 4.6.

  • BTC Drops Below $74,000

    Market data shows that BTC has fallen below $74,000, currently priced at $73,989.92, with a 24-hour increase of 0.08%. The market is experiencing significant volatility, so please ensure proper risk management.

  • WTI Crude Oil Surpasses $93 per Barrel

    WTI crude oil has surpassed $93 per barrel, rising 1.71% during the day; Brent crude oil has increased by over 2.00% during the day, currently priced at $94.14 per barrel. (Jin Shi)

  • ETH Falls Below $2300

    Market data shows that ETH has fallen below $2300, currently priced at $2298.7, with a 24-hour decline of 0.98%. The market is experiencing significant fluctuations, so please ensure proper risk management.