Drift, a Solana-based decentralized exchange, disclosed a major cyberattack resulting in losses estimated at about $280 million. Analysts attribute the breach to UNC4736, a North Korea–linked hacking group, which allegedly advanced its methods by cultivating months-long relationships with exchange insiders through fake firms and intermediaries. The operation blended offline and online interactions across multiple countries, culminating in access to Drift’s internal systems.
The attackers reportedly posed as a sophisticated software outfit providing automated trading services, attending industry events and gradually earning trust by demonstrating expertise. Drift indicated the firm was onboarded from late 2025 into early 2026, and by early 2026 representatives met at conferences, reinforcing the perception of a trusted partner. Eventually, internal access was gained and the group allegedly exploited vulnerabilities to carry out the hack, with some members copying code repositories or downloading applications.
Experts describe this as a notable evolution in North Korean cyber operations, emphasizing human-based intrusion over purely technical breaches. Michael Vanhart of Detex called the approach unprecedented for its duration and offline trust-building, predicting more sophisticated campaigns against crypto platforms and wallets. Security professionals are urging stronger defenses against social engineering, supply-chain attacks, and phishing, and they note the broader geopolitical dimension of crypto-targeted threats tied to North Korea and similar actors.















Leave a Reply