Drift Protocol Exploited for $280 Million in April Fools’ Attack
CryptoDnes
19h ago

Author:CryptoDnes

Drift Protocol suffered a $280 million exploit on April 1, 2026. Investigators link the attack to the UNC4736 group using sophisticated social engineering.

The hacking attack against Drift on April 1, 2026, which saw $280 million stolen, initially caused surprise due to its timing. What some dismissed as a potential April Fools’ joke was later confirmed as one of the most serious security breaches in decentralized finance this year.

How the Hack Unfolded

The attackers established initial contact as early as the fall of 2025 at a major crypto conference, posing as a quantum trading company. They demonstrated a high technical level, convincing professional profiles, and a deep understanding of the protocol, which led to the establishment of communication and subsequent professional interactions.

Between December 2025 and January 2026, the group integrated themselves into the Drift ecosystem, creating their own vault, participating in developer meetings, and depositing over $1 million of their own capital. Their presence was further solidified through face-to-face meetings at industry events in several countries.

The Attack: A Mix of Social Engineering and Technical Exploits

The compromise was carried out through two primary vectors. One involved exploiting a vulnerability in popular development environments such as Visual Studio Code and Cursor, where opening a file could lead to the immediate execution of malware without warning.

The second vector involved an application distributed through TestFlight, presented as a crypto wallet, which bypassed standard App Store checks.

After compromising the devices, the attackers managed to obtain the necessary approvals for multi-sig transactions. Pre-signed operations remained dormant for more than a week before being executed on April 1, draining the funds in less than a minute.

The investigation links the attack to the UNC4736 group, also known as AppleJeus or Citrine Sleet, based on blockchain analysis and operational similarities with previous attacks.

Interestingly, the participants who met the team in person were not North Korean citizens. Such groups often use intermediaries with established fake identities and professional histories capable of withstanding background checks.

Drift warned that any access to multi-sig infrastructure must be viewed as a potential attack point. The case highlights a broader issue for the industry—whether current security models are sufficient against adversaries willing to invest time, resources, and trust to achieve a breach.

Tip
$0
Like
0
Save
0
Views 117
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Drift Protocol Hit By $280M Exploit As Sophisticated Attack Targets Governance Controls
Drift Protocol, a Solana-based perpetuals trading platform, is dealing with the fallout of a major…
nulltx
·2026-04-03 00:14:03
108
Drift links $280 million exploit to six-month social engineering op run by suspected North Korean actors
With "medium-high" confidence, Drift and the SEAL 911 team assess the operation was run by the same North Korean actors behind the Radiant Capital hack.
The Block
·2026-04-06 01:00:00
920
Drift Protocol's $285 Million Hack Came After Six Months of North Korean Infiltration
Drift Protocol revealed a sophisticated six-month intelligence operation by a North Korean state-affiliated group that drained $285 million. The attackers used fabricated identities and malicious tools to compromise contributors before executing the drain.
Decrypt
·2026-04-06 17:52:05
303
How the Drift Protocol Exploit Hit 20 Solana Projects
Coin Gabbar
·2026-04-03 14:00:04
290
Spur Protocol Daily Quiz Answer 04 April 2026: Earn Rewards
Coin Gabbar
·2026-04-04 00:00:04
327