← Radar

Incident case file

Sign in to watch

Drift Protocol — DPRK 6-Month Social Engineering Admin Takeover

Incident date April 1, 2026

0 views

Funds movingSolanaEthereumSocial engineering / Private keyCluster: DPRK-UNC4736-2026-04

Estimated loss

$285M

Victims identified

32
Victim group joining is coming soon.

Investigation

20%

Facts and investigation

Attacker: HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES (Solana)

Funds moved to: Jupiter DEX → USDC → bridged to Ethereum → converted to ETH → Hyperliquid + Binance. Attacker ETH wallet held 19,913 ETH (~$42.6M) within hours.
Compromised admin address H7PiGqqUaanBovwKgEtreJbKmQe6dbq6VTrw6guy7ZgL. Fake CVT token contract (deployed March 12, funded via Tornado Cash March 11). Pre-attack infrastructure funded with ~$1M withdrawn from Tornado Cash.

Timeline: Autumn 2025 — DPRK operatives (UNC4736) infiltrate Drift's social circle at conferences, deposit >$1M to build trust. March 11, 2026 — Tornado Cash withdrawal funds CVT token deployment. March 12 — CarbonVote (CVT) fake token deployed on Raydium, wash-traded to maintain ~$1 price. March 27 — Security Council migrated to 2/5 multisig with zero timelock, eliminating detection window. March 30 — Attacker re-establishes quorum via durable nonce account. April 1, 16:05:18 UTC — Pre-signed durable nonce transaction executes admin key transfer. 16:05–16:17 UTC — 31 withdrawal transactions drain all vaults in 12 minutes ($285M). April 2 — Drift confirms breach, engages Mandiant. April 5 — Drift attributes attack to UNC4736 with medium-high confidence.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)