CSIDB logo
Incident

Drift Protocol

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 02:41

Linked entities

Victim
Drift Protocol
Threat actors
2 actors
Sources
6 sources

Timeline

Occurred
Apr 2026
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Pending

Summary

Drift Protocol was compromised after a months‑long social engineering operation that gave attackers access to privileged keys, allowing them to mint counterfeit tokens and inflate borrowing limits before draining hundreds of millions of dollars in assets. The exploit relied on compromised infrastructure rather than smart‑contract vulnerabilities and was linked to a North Korean‑backed group that used fabricated credentials and manipulated price‑oracle feeds to siphon funds. The incident contributed to a concentration of losses, with a single pair of attacks accounting for nearly half of all crypto thefts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In mid‑March 2026 attackers began moving funds through the mixing service Tornado Cash to obscure their trail and established special accounts to prepare future transactions. On March 27 the Drift security team altered its approval mechanism, reducing the required signatures from five to two of five key holders and eliminating any built‑in waiting period that might have triggered an alert. Taking advantage of this change, the attackers minted 750 million brand‑new tokens labeled CarbonVote Token (CVT) and manipulated the platform’s trading activity so that its price‑checking algorithms treated these worthless tokens as legitimate, high‑value collateral capable of backing large withdrawals. On April 1 they executed the pre‑prepared transactions, adding the fake CVT token to the protocol, raising borrowing limits, flooding the system with hundreds of millions of the phony tokens and draining real assets through 31 rapid withdrawals, a process that lasted approximately twelve minutes. The stolen funds were quickly swapped for USDC on a Solana‑based exchange and then bridged to the Ethereum network to hinder traceability.

The breach resulted in the loss of roughly $285 million from Drift’s storage pools, which held stablecoins such as USDC alongside JLP, SOL and other crypto assets. Immediately after the attack Drift suspended its services and issued a public update on X detailing the six‑month intelligence operation that had preceded the exploit. Blockchain analysis firms TRM Labs and Elliptic reconstructed the transaction flow, noting on‑chain activity that aligned with Pyongyang local time and behavioral patterns consistent with prior North Korean‑linked operations. Forensic review identified three plausible vectors for the private‑key compromise: a contributor possibly cloning a code repository that exploited a known VSCode or Cursor vulnerability to run arbitrary code silently, another individual being persuaded to download a TestFlight app masquerading as the firm’s wallet product, and a third vector still under active law‑enforcement investigation. With medium‑to‑high confidence the SEAL 911 team linked the effort to the same North Korean state‑affiliated actors responsible for the October 2024 Radiant Capital hack, noting that the individuals who interacted with Drift staff were third‑party intermediaries rather than North Korean nationals.

The Drift incident contributed to April 2026 becoming the worst month on record for crypto hacks, as the combined losses from Drift and the Kelp DAO exploit approached $579 million. TRM Labs reported that 76 percent of all cryptocurrency stolen in 2026 was traced to North Korea, attributing this share solely to the Drift and Kelp DAO attacks. The attack mirrored earlier exploits such as the Resolv protocol breach, where control of a privileged signing key enabled the minting of excessive tokens against minimal collateral, underscoring that the breach stemmed from private‑key access and infrastructure weaknesses rather than a smart‑contract flaw. Drift’s subsequent communications emphasized that the operation involved prolonged social engineering, the establishment of a Telegram group posing as a quantitative trading firm, and the onboarding of an Ecosystem Vault with over $1 million in deposits before the group erased its communications after the theft. The episode prompted broader discussion within the crypto sector about the vulnerability of governance mechanisms and key‑management practices to sophisticated, state‑backed social engineering campaigns. No further speculative or advisory content is included beyond these verified facts.

Sources

Sources available to members: 6 sources.

CSIDB