How North Korea Stole $270 Million from Drift Protocol Over Six Months

Key Takeaways

  • A North Korean state-linked group (UNC4736 / Citrine Sleet) spent roughly six months building a fake trading firm identity before draining $270 million from Drift Protocol on April 1, 2026.
  • Attackers met Drift contributors in person at conferences across multiple countries, deposited over $1 million of real capital, and integrated an Ecosystem Vault to build legitimate trust.
  • The compromise came through a malicious TestFlight app and a known VSCode/Cursor vulnerability that silently executed code when a file was opened.
  • The incident raises hard questions about whether multisig governance, the DeFi industry’s go-to security model, can hold up against patient, well-resourced state actors.

Most crypto hacks follow a familiar pattern. Someone finds a smart contract vulnerability, writes an exploit, and drains funds in a matter of blocks. The whole thing is over before most people finish their morning coffee. The Drift Protocol attack was nothing like that.

What Drift published on Sunday reads less like a post-mortem and more like an intelligence briefing. A North Korean state-affiliated group, tracked by security researchers as UNC4736 and also known as Citrine Sleet or AppleJeus, spent approximately six months building a fake quantitative trading firm, meeting Drift contributors face to face at conferences across multiple countries, depositing over a million dollars of real capital into the protocol, and then waiting. They executed the drain on April 1 and it was done in under a minute. $270 million gone.

What Actually Happened

The operation started in fall 2025 at a major crypto conference. The attackers showed up presenting themselves as a quant trading firm interested in integrating with Drift. They were technically fluent, had constructed professional backgrounds, and knew how the protocol worked. A Telegram group was set up and months of substantive conversations followed, the kind of normal back-and-forth that happens when trading firms onboard with DeFi protocols.

By December and January, they had onboarded an Ecosystem Vault, held working sessions with contributors, and deposited real capital. Real money. They weren’t just pretending. Between February and March, members of the group met Drift contributors in person at multiple industry events. By April, the relationship was close to six months old and, from the outside, completely legitimate.

The technical compromise came through two vectors. One involved a TestFlight application, Apple’s pre-release app distribution platform that bypasses App Store review. The group presented it as their wallet product. The other was a known vulnerability in VSCode and Cursor (two of the most widely used code editors in software development) where simply opening a file or folder was enough to silently execute arbitrary code. No warning, no prompt. The security community had been flagging this since late 2025.

Once they had compromised devices, they obtained the two multisig approvals they needed to execute a durable nonce attack. Those pre-signed transactions sat dormant for more than a week before the attackers pulled the trigger on April 1. The whole drain took less than sixty seconds.

Why This Matters Beyond DeFi

It’s tempting to file this under “crypto problems for crypto people,” but the implications reach further than that. This is a nation-state running a sophisticated, long-horizon social engineering operation against a financial protocol. The attackers didn’t just build fake LinkedIn profiles. They deployed intermediaries with fully constructed identities, verifiable employment histories, and professional networks capable of withstanding real due diligence. The people who showed up in person at those conferences were not North Korean nationals.

That level of operational sophistication costs money and takes time to build. The group spent over a million dollars of their own capital just to establish credibility. This wasn’t opportunistic. It was planned and patient in a way that most security models simply aren’t designed to anticipate.

For anyone thinking about enterprise security more broadly, the VSCode/Cursor vulnerability is worth attention on its own. Developers across every industry use these tools. A silent code execution triggered by opening a file is a meaningful exposure, and the fact that it was already a known issue in late 2025 makes it more uncomfortable, not less.

The Harder Question About Multisig

Drift made a point of flagging this explicitly: if attackers are willing to spend six months and a million dollars building a legitimate presence inside an ecosystem, meet the team in person, contribute real capital, and wait, what security model actually catches that?

Multisig has been the consensus answer for DeFi governance security for years. The assumption is that requiring multiple parties to sign off on transactions prevents any single point of failure. That logic holds up fine against most attack vectors. It does not hold up particularly well when the attacker has already compromised the devices of the people doing the signing.

The Drift incident doesn’t mean multisig is worthless. But it does suggest the industry has been treating it as something closer to a complete solution than it actually is. Hardware signing, air-gapped key management, and device security hygiene for anyone touching a multisig key are conversations that have existed at the margins of DeFi security discussions for a while. They may need to move toward the center.

Where This Leaves Things

Attribution in these cases often gets complicated and sometimes contested, but the on-chain fund flows traced back to the Radiant Capital attackers and the operational patterns match known DPRK-linked groups. Whether or not every detail gets confirmed, the attack itself happened. The money is gone.

Drift has urged other protocols to audit access controls and treat every device with multisig access as a potential target. That’s practical advice, though the harder problem is that the attack surface here isn’t purely technical. It’s human. Six months of relationship-building, in-person meetings, real financial commitment. Standard security audits don’t screen for that.

The DeFi space has dealt with plenty of exploits over the years and has generally gotten better at the technical side of security. Smart contract audits are now standard. Bug bounty programs are common. The human intelligence layer is murkier territory, and incidents like this one make it harder to argue that’s someone else’s problem to solve.

None of this makes building in this space impossible. But it does mean the threat model needs to be wider than most teams are currently accounting for.

If you liked this post, you’ll love one of the the leading global business communications and technology events since 1999, the ITEXPO #TECHSUPERSHOW, Feb 10-12, 2026 Fort Lauderdale, Florida.

Don’t forget the collocated MSP Expo – just for managed service providers!

Aside from his role as CEO of TMC and chairman of ITEXPO #TECHSUPERSHOW Feb 10-12, 2026, Rich Tehrani is CEO of RT Advisors and a Registered Representative (investment banker) with and offering securities through Four Points Capital Partners LLC (Four Points) (Member FINRA/SIPC). He handles capital/debt raises as well as M&A. RT Advisors is not owned by Four Points.

The above is not an endorsement or recommendation to buy/sell any security or sector mentioned. No companies mentioned above are current or past clients of RT Advisors.

The views and opinions expressed above are those of the participants. While believed to be reliable, the information has not been independently verified for accuracy. Any broad, general statements made herein are provided for context only and should not be construed as exhaustive or universally applicable.

Portions of this article may have been developed with the assistance of artificial intelligence, which may have contributed to ideation, content generation, factual review, or editing


 

Loading
Share via
Copy link
Powered by Social Snap