Cointime

Download App
iOS & Android

Crypto attorney says Drift incident may qualify as 'civil negligence'

The hack of the Solana-based decentralized finance (DeFi) platform Drift Protocol could have been prevented if standard operational security procedures were followed by the Drift team, and may constitute “civil negligence,” according to attorney Ariel Givner.

“In plain terms, civil negligence means they failed their basic duty to protect the money they were managing,” Givner said in response to the post-mortem update provided by the Drift team and how it handled Wednesday’s $280 million exploit.

The Drift team failed to follow “basic” security procedures, including keeping signing keys on separate, “air-gapped” systems that are never used for developer work, and conducting due diligence on blockchain developers met through industry conferences.

  Source: Ariel Givner


“Every serious project knows this. Drift didn’t follow it,” she said, adding, “They knew crypto is full of hackers, especially North Korean state teams.” Givner continued: 

“Yet their team spent months chatting on Telegram, meeting strangers at conferences, opening sketchy code repos, and downloading fake apps on devices tied to multisignature controls.”

Advertisements for class action lawsuits against Drift Protocol are already circulating, she said. Cointelegraph reached out to the Drift Team but did not receive a response by the time of publication.

  Source: Ariel Givner


The incident is a reminder that social engineering and project infiltration by malicious actors are major attack vectors for cryptocurrency developers that could drain user funds and permanently erode customer trust in compromised platforms.

Drift Protocol says attack took “months” of planning

The Drift Protocol team published an update on Saturday outlining how the exploit occurred and claimed that the attackers planned the attack for six months before execution.

Threat actors first approached the Drift team at a “major” crypto industry conference in October 2025, expressing interest in protocol integrations and collaboration.

The malicious actors continued to build rapport with the Drift development team in the ensuing six months, and once enough trust was built, they began sending the Drift team malicious links and embedding malware that compromised developer machines.These individuals, who are suspected of working for North Korea state-affiliated hackers and physically approached the Drift developers, were not North Korean nationals, according to the Drift team.

Drift said, with “medium-high confidence,” that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.

In December 2024, Radiant Capital said the exploit was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor. 

Comments

All Comments

Recommended for you

  • BTC Surpasses $70,000

    Market data shows that BTC has surpassed $70,000, currently priced at $70,003.25, with a 24-hour increase of 3.96%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Iran Responds to the U.S. via Pakistan, Rejects Ceasefire, Emphasizes Need for Permanent End to War

    According to the Islamic Republic News Agency (IRNA): Iran has responded to the United States through Pakistan, rejecting a ceasefire and emphasizing the necessity for a permanent end to the war.

  • US Media: 45-Day Ceasefire Plan is Just One of Many Proposals

    According to US media reports on the 6th, a White House official stated that the 45-day ceasefire plan between the US and Iran is just one of the 'many proposals' currently under discussion. The official indicated that President Trump has not yet approved the plan, and US military actions against Iran are still ongoing. (Xinhua News Agency)

  • Trump Has Not Approved Ceasefire Plan

    On April 6, the White House stated that President Trump has not yet approved the ceasefire plan. The potential ceasefire proposal is just one of many ideas.

  • Strategy Increases BTC Holdings by 4,871 Last Week, Total Holdings Exceed 766,000

    On April 6, Strategy officially disclosed that last week it purchased 4,871 BTC at an average price of approximately $67,718, with a total expenditure of about $329.9 million. As of 2026, Strategy has accumulated a total of 766,970 BTC, with a total holding cost of approximately $58.02 billion, resulting in an average price of about $75,644 per coin.

  • Iran Launches 98th Wave of 'True Commitment-4' Offensive Against US Amphibious Assault Ship

    On April 6, the Public Relations Department of the Iranian Islamic Revolutionary Guard Corps announced that Iran has launched the 98th wave of the 'True Commitment-4' operation. The statement indicated that the naval forces of the Islamic Revolutionary Guard Corps used cruise missiles to strike the container ship SDN7, which belongs to the 'Zionist regime.' Following its destruction, a large fire broke out. Additionally, missiles targeted strategic centers in northern and southern Tel Aviv, Haifa, chemical enterprises and factories in Be'er Sheva, as well as military installations in Batehfael. The statement also mentioned that the US amphibious assault ship LHA7, carrying over 5,000 sailors and Marines, was hit by missiles and was forced to retreat to deep waters in the southern Indian Ocean after the offensive. Furthermore, the UAE-Israel joint drone production center and several aircraft stationed at Ali Salim base were also subjected to drone and missile strikes.

  • Vessel Traffic in the Strait of Hormuz Reaches Highest Level Since Early March

    On April 6, foreign media reported that traffic through the Strait of Hormuz has risen to its highest level since the onset of the Middle East conflict, as more countries have reached security passage agreements with Iran. Over the weekend, a total of 21 vessels passed through the waterway, marking the highest two-day total since traffic began to decline in early March. Although the current number of vessels is still far below pre-war levels (approximately 135 vessels), more countries have obtained passage permits. A senior crude oil analyst at Singapore's Kpler stated, 'Iran is strengthening its control over Hormuz while responding to requests from its partners. Passage still depends on Iran's willingness, and the situation could change at any time if the conflict escalates.' So far, most of the vessels granted passage appear to be following the routes indicated by Tehran, navigating close to the Iranian coast. However, more vessels are also beginning to choose to travel along the opposite shore.

  • Iran Calls U.S. 15-Point Plan 'Highly Ambitious and Illogical'

    April 6 - According to the Islamic Republic News Agency (IRNA), Iranian Foreign Ministry spokesman Ismail Baghaei stated that in the context of recent proposals to end the war, Tehran has finalized its demands but will only announce them at the appropriate time, emphasizing that Iran will not succumb to pressure. He said, 'A few days ago, they proposed some plans through intermediaries, and this U.S. plan, which contains 15 points, was conveyed through Pakistan and other friendly countries.' He added, 'Such proposals are highly ambitious, unusual, and illogical.' He stressed that Iran has its own framework. 'Based on our own interests and considerations, we have organized and formulated a series of demands that we have presented in the past and present.' He also denied that engaging with mediators indicates weakness. 'The fact that Iran quickly and courageously expressed its position on a proposal should not be seen as a sign of submission to the enemy.' (Jinshi)