Incident case file
Sign in to watchDrift Protocol — DPRK 6-Month Social Engineering Admin Takeover
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES (Solana)
Timeline: Autumn 2025 — DPRK operatives (UNC4736) infiltrate Drift's social circle at conferences, deposit >$1M to build trust. March 11, 2026 — Tornado Cash withdrawal funds CVT token deployment. March 12 — CarbonVote (CVT) fake token deployed on Raydium, wash-traded to maintain ~$1 price. March 27 — Security Council migrated to 2/5 multisig with zero timelock, eliminating detection window. March 30 — Attacker re-establishes quorum via durable nonce account. April 1, 16:05:18 UTC — Pre-signed durable nonce transaction executes admin key transfer. 16:05–16:17 UTC — 31 withdrawal transactions drain all vaults in 12 minutes ($285M). April 2 — Drift confirms breach, engages Mandiant. April 5 — Drift attributes attack to UNC4736 with medium-high confidence.
Sources and coverage
- Articlechainalysis.comhttps://www.chainalysis.com/blog/lessons-from-the-drift-hack/
- Articletrmlabs.comhttps://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist
- Articleelliptic.cohttps://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack
- Articlethehackernews.comhttps://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html
- Articlecoindesk.comhttps://www.coindesk.com/tech/2026/04/02/how-a-solana-feature-designed-for-convenience-let-an-attacker-drain-usd270-million-from-drift
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)