- $280M Drift exploit linked to 6-month social engineering campaign
- Attackers posed as legitimate trading firm
- Likely tied to North Korean hacking group
- Exploit used pre-approved transactions, not smart contract bugs
A highly coordinated attack
The $280 million exploit on Drift Protocol has been linked to a long-running social engineering campaign that began months before the actual attack.
Attackers built trust with contributors by posing as a legitimate trading firm, attending conferences, and interacting with the team over time.
How the exploit happened
Instead of exploiting a smart contract flaw, attackers gained access through compromised devices and manipulated approvals.
They used pre-signed transactions and control over administrative permissions to drain funds quickly once access was secured.
North Korea connection
Investigators believe the attack is linked to North Korean-backed hacking groups, based on similarities in behavior, infrastructure, and fund flows.
These groups are known for targeting crypto projects using advanced social engineering tactics rather than purely technical exploits.
A new type of risk in crypto
The incident shows that the biggest threats are no longer just code vulnerabilities, but human factors such as trust, communication, and access control.
It also suggests that more protocols could be vulnerable to similar long-term infiltration strategies.