Cointime

Download App
iOS & Android

Drift Protocol says $280M exploit took 'months of deliberate preparation'

Drift Protocol, the decentralized exchange (DEX) that lost an estimated $280 million in an exploit last week, claims the loss was the result of a six-month, highly coordinated attack.

“The preliminary investigation shows that Drift experienced a structured intelligence operation requiring organizational backing, significant resources, and months of deliberate preparation,” Drift said in an X post on Saturday.

Attack began at a “major crypto conference”

According to Drift, the attack can be traced back to around October 2025, when malicious actors posing as a quantitative trading firm first approached Drift contributors at a “major crypto conference,” claiming to be interested in integrating with the protocol.

  Source: Drift Protocol


The group continued to engage contributors in person at multiple industry events over a six-month period. “It is now understood that this appears to be a targeted approach, where individuals from this group continued to deliberately seek out and engage specific Drift contributors,” Drift said.

“They were technically fluent, had verifiable professional backgrounds, and were familiar with how Drift operated,” Drift said.

After gaining trust and access to Drift Protocol over six months, they used shared malicious links and tools to compromise contributors’ devices, execute the exploit, and then wiped their presence immediately after the attack.

The incident serves as a reminder for crypto industry participants to remain cautious and skeptical, even during in-person interactions, as crypto conferences can be prime targets for sophisticated threat actors.

Drift flags a high probability of a Radiant Capital hack link

Drift said, with “medium-high confidence,” that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.

In December 2024, Radiant Capital said the exploit was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor. 

  Source: Dith


“This ZIP file, when shared for feedback among other developers, ultimately delivered malware that facilitated the subsequent intrusion,” Radiant Capital said.

Drift said that the individuals who appeared in person “were not North Korean nationals.”

“DPRK threat actors operating at this level are known to deploy third-party intermediaries to conduct face-to-face relationship-building,” Drift said.

Drift said that it is working with law enforcement and others in the crypto industry to “build a complete picture of what happened during the April 1st attack.”

Comments

All Comments

Recommended for you

  • Iran Calls U.S. 15-Point Plan 'Highly Ambitious and Illogical'

    April 6 - According to the Islamic Republic News Agency (IRNA), Iranian Foreign Ministry spokesman Ismail Baghaei stated that in the context of recent proposals to end the war, Tehran has finalized its demands but will only announce them at the appropriate time, emphasizing that Iran will not succumb to pressure. He said, 'A few days ago, they proposed some plans through intermediaries, and this U.S. plan, which contains 15 points, was conveyed through Pakistan and other friendly countries.' He added, 'Such proposals are highly ambitious, unusual, and illogical.' He stressed that Iran has its own framework. 'Based on our own interests and considerations, we have organized and formulated a series of demands that we have presented in the past and present.' He also denied that engaging with mediators indicates weakness. 'The fact that Iran quickly and courageously expressed its position on a proposal should not be seen as a sign of submission to the enemy.' (Jinshi)

  • BTC Surpasses $70,000 Mark

    Market data shows that BTC has surpassed the $70,000 mark, currently priced at $70,071.01, with a 24-hour increase of 4.46%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Dollar Index Falls Below 100 Mark

    On April 6, the Dollar Index (DXY) dropped below 100, declining by 0.21% during the day to report at 99.99 points.

  • BTC Falls Below $69,000

    Market data shows that BTC has fallen below $69,000, currently priced at $68,995.66, with a 24-hour increase of 3.38%. The market is experiencing significant volatility, so please ensure proper risk management.

  • US-Iran Ceasefire Agreement Expected to Take Effect on April 6

    On April 6, Reuters cited a source stating that the United States and Iran have received a proposal for a ceasefire agreement, which may take effect on the same day. The source indicated that Pakistan has drafted a framework to end the conflict and has communicated with both the US and Iran. The proposal aims for an immediate ceasefire and the reopening of the Strait of Hormuz, followed by a final agreement to be reached within 15 to 20 days. The final agreement may include Iran's commitment not to seek nuclear weapons in exchange for the lifting of sanctions and the unfreezing of assets.

  • Robert Kiyosaki recommends Bitcoin, gold as 1974 shift comes full circle

    The Rich Dad Poor Dad author continues to back Bitcoin, gold and silver as alternatives to traditional money.

  • Crypto attorney says Drift incident may qualify as 'civil negligence'

    The $280 million Drift Protocol attack was likely carried out by threat actors aligned with North Korea state-affiliated hackers.

  • BTC Surpasses $69,000

    Market data shows that BTC has surpassed $69,000, currently priced at $69,019.99, with a 24-hour increase of 2.61%. The market is experiencing significant volatility, so please ensure proper risk management.