CSIDB logo
Threat actor

Citrine Sleet

Attribution profile

Type
Nation State
Location
North Korea
Known incidents
2 incidents
First seen
2026-04-01
Last seen
2026-04-18
Updated
2026-08-26 23:44
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Citrine Sleet is a threat actor alias associated with North Korean state‑linked cyber operations. The actor has been observed targeting decentralized finance platforms, particularly those built on blockchain networks such as Solana and Ethereum, with the apparent strategic objective of illicit financial gain through the theft of digital assets. Known activity focuses on exploiting vulnerabilities in protocol governance and private‑key management to divert funds, indicating a clear financial motivation rather than espionage or disruption. The actor’s operational footprint is tied to the Democratic People’s Republic of Korea, as publicly attributed by investigators who linked the activity to prior North Korean‑linked hacks.

In the compromise of the Drift perpetual futures protocol, Citrine Sleet employed a prolonged six‑month social engineering campaign to gain trust and eventually obtain private‑key access. Initial intrusion vectors included a compromised code repository, a malicious TestFlight wallet application, and an undisclosed additional method that together facilitated credential harvesting. Once inside, the actors altered the protocol’s approval mechanism to reduce the required signatures from five to two and removed any time delay, enabling the unauthorized minting of 750 million fake CarbonVote tokens. These tokens were used as collateral to inflate borrowing limits, after which the attackers executed rapid withdrawals of stablecoins and other assets, converting the proceeds to USDC on Solana, bridging them to Ethereum, and routing the funds through a mixing service to obscure the trail before the protocol suspended operations.

Attribution to North Korea is explicitly stated in public reporting, establishing a clear state nexus for Citrine Sleet’s activities. The Drift incident is cited as a representative example of the actor’s capability to conduct sophisticated, financially motivated campaigns against emerging financial technologies. Investigators have noted that this operation fits within a broader pattern of North Korean‑linked cryptocurrency heists, suggesting a recurring focus on exploiting decentralized finance ecosystems to generate revenue for the regime. The combination of social engineering, supply‑chain compromise, and manipulation of smart‑contract governance constitutes the observed TTP profile for this actor, reflecting a methodical approach to acquiring and liquidating digital assets.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB