Drift Protocol Reveals 6-Month Infiltration Behind $285M Theft

Creator:

Drift Protocol

Quick Read

  • Drift Protocol revealed a six-month infiltration operation behind the $285 million theft.
  • Attackers posed as a trading firm, compromising devices via malicious links and TestFlight.
  • The operation is suspected to be linked to the North Korean-linked group behind the Radiant Capital theft.

YEREVAN (Azat TV) – Drift Protocol has released the findings of its investigation into the $285 million theft, revealing a sophisticated, six-month infiltration operation believed to be orchestrated by a North Korean-linked hacking group. The attackers posed as a quantitative trading firm, engaging with Drift team members over an extended period and ultimately compromising devices through malicious links and the TestFlight application.

Sophisticated Six-Month Infiltration Uncovered

The investigation indicates that the breach was not a swift attack but a prolonged, meticulously planned operation that began around the fall of 2025. Hackers reportedly made contact with Drift team members at various international crypto conferences, building a facade of legitimacy. This long-term engagement allowed them to progressively compromise devices. The method involved sharing code repository links and utilizing the TestFlight application, a common tool for beta testing software, to introduce malicious code.

Suspected Link to Previous Major Heist

Drift Protocol’s findings suggest a potential connection to the hacking group responsible for the 2024 theft of Radiant Capital. This linkage points towards a pattern of sophisticated cybercrime targeting decentralized finance platforms, often attributed to state-sponsored or state-affiliated entities operating with significant resources and patience. The scale and duration of the infiltration underscore the evolving tactics of cybercriminals in the cryptocurrency space.

Impact and Ongoing Security Concerns

The revelation of a six-month infiltration highlights the significant security challenges faced by blockchain protocols. The attackers’ ability to maintain their cover and systematically gain access to sensitive systems demonstrates a high level of technical expertise and operational security. The theft of $285 million represents a substantial loss, impacting investor confidence and underscoring the constant need for vigilance and advanced security measures within the digital asset industry. The protocol continues to assess the full scope of the breach and implement enhanced security protocols to prevent future incidents.

The discovery of a prolonged, six-month infiltration by a North Korean-linked group, posing as a legitimate trading firm, signifies a dangerous escalation in the sophistication and patience employed by cybercriminals targeting the decentralized finance sector.

LATEST NEWS