Drift Protocol's $285 Million Exploit Tied to Suspected North Korean Hackers
Regulation

Drift Protocol's $285 Million Exploit Tied to Suspected North Korean Hackers

03 Sep 2026, 06:30 2 views Admin

Investigators suspect North Korean-affiliated hackers used a long-term social engineering campaign with pre-signed hidden authorizations to drain $285 million from Drift Protocol.

<p>The $285 million exploit of Drift Protocol on April 1 has been linked by investigators to suspected North Korean-affiliated hackers, who authorities believe executed a sophisticated, long-term social engineering campaign involving pre-signed hidden authorizations rather than a straightforward smart contract exploit. The attack ranks as the second-largest DeFi hack of 2026, behind only the $293 million Kelp DAO exploit.</p>
<p>The attack method described by investigators -- obtaining pre-signed hidden authorizations through extended social engineering -- represents a more patient and human-focused attack vector than the smart contract bugs that have historically dominated headline DeFi exploits. Rather than exploiting a flaw in the protocol's code directly, this approach reportedly involved manipulating individuals with privileged access over an extended period to obtain authorization credentials that could later be used to drain funds.</p>
<p>North Korean state-linked hacking groups have been repeatedly implicated in major crypto thefts over the past several years, with blockchain analytics firms and government agencies attributing billions of dollars in cumulative crypto theft to North Korean operations believed to fund the country's weapons programs amid international sanctions. The Drift Protocol attack, if confirmed as North Korean-linked, would extend that established pattern into 2026's largest DeFi exploits.</p>
<p>Security researchers have noted that attacks relying on social engineering and compromised access credentials, rather than pure code vulnerabilities, have become an increasingly dominant category of crypto theft in 2026. Data on the year's largest incidents shows that compromised keys, permissions, and privileged rights -- rather than smart contract bugs specifically -- have driven a disproportionate share of total losses, suggesting that human and access-control vulnerabilities have surpassed pure code exploits as the primary threat facing both centralized and decentralized platforms.</p>
<p>For DeFi protocols generally, the Drift Protocol incident reinforces the need for security practices that extend beyond code audits to include operational security around privileged access, multi-signature requirements, and defenses against long-term social engineering campaigns targeting team members with elevated permissions -- a threat model that traditional smart contract auditing alone is not designed to catch.</p>
Share