'Terrifying': Solana Founder Reacts to One of Biggest DeFi Hacks in History
U.Today
17h ago

Author:Blockchain Pioneer

Solana co-founder Anatoly Yakovenko has described the recent Drift Protocol hack as "terrifying" after it was revealed that it was the result of a sophisticated social engineering attack that was pulled off by North Korean hackers. 

As reported by U.Today, Drift Protocol was recently drained of $270 million, which is the largest Solana hack to date within the ecosystem. The protocol was forced to halt all deposits and withdrawals, explicitly warning users that the incident was not an April Fools' joke.

Six months in the making 

The report, which was recently shared by Drift Protocol, has revealed that the bad actors behind the historic hack physically stalked and socially engineered the developers in real life. This required alarming patience and resources. 

The operation is heavily suspected to be the work of a North Korean state-affiliated threat group. 

Starting in late 2025, third-party intermediaries (who were not North Korean nationals) physically approached Drift contributors at major crypto conferences. The attackers, who boasted verifiable professional backgrounds and technical fluency, posed as a quantitative trading firm looking to integrate with the protocol. 

The fake trading firm onboarded an Ecosystem Vault on Drift between December 2025 and January 2026 and deposited more than $1 million of their own capital. 

The attackers had managed to maintain the illusion for half a year. They were working closely with Drift contributors through multiple working sessions and meeting them face-to-face at various international conferences through February and March 2026.

By April, the attackers had successfully established a trusted business relationship. The Drift contributors did not suspect foul play when the group shared links to projects they claimed to be building.

One contributor cloned a code repository shared by the attackers. This repository likely contained a known vulnerability affecting the VSCode and Cursor text editors. A second contributor was convinced to download a fake TestFlight application.

The attackers scrubbed all of their Telegram chats and wiped the malicious software after the successful exploit.

Tip
$0
Like
0
Save
0
Views 169
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
The "Key to God" in DeFi: The $285 Million Theft from Drift Reveals the Biggest Vulnerability in Decentralized Finance
Drift's move has struck a wound that the industry least wants to face.
TechFlow
·2026-04-02 09:47:57
355
Solana DeFi Hack Puts Spotlight On Ripple’s Swift-Linked XRP Strategy
dailycoin
·2026-04-03 00:00:00
654
Bitcoin’s Bottom Signals Are Not Confirmed: Biggest Buyers Are Not Waiting
Bitcoin's traditional bottom confirmation signals have not fired. The z-score is still positive. The Coinbase Premium is deeply negative. The Market Heat Score is silent.
Coindoo
·2026-04-05 15:37:00
576
Apple has become the biggest enemy of Vibe Coding entrepreneurs.
Vibe Coding promises a future where ordinary people can create software. This future is coming, but on Apple's turf, it needs a license first.
Wall Street CN
·2026-04-04 11:02:54
822
Vitalik Buterin Not Biggest Individual Holder of Ethereum, New Data Shows
U.Today
·2026-04-03 13:16:00
780