Preliminary investigation into the Drift hacking incident shows that team members were contacted by North Korean intermediaries during a meeting.

robot
Abstract generation in progress

ME News Report, April 5th (UTC+8), Drift Protocol posted on X platform stating that preliminary investigations into the April 1, 2026 attack indicate the operation was orchestrated by the North Korean government-backed hacker group UNC4736 (also known as AppleJeus or Citrine Sleet).
Since fall 2025, the group has engaged in face-to-face interactions with Drift contributors for up to six months by dispatching intermediaries to participate in crypto conferences, establishing fake quantitative trading firms, and other methods, during which they induced downloads of malicious code repositories or applications.
Currently, Drift has frozen all protocol functions and removed the compromised wallets from multi-signature.
Mandiant has been invited to participate in an in-depth forensic investigation.
The investigation confirmed that the on-chain fund flows used to test this operation trace back to the Radiant Capital attacker from October 2024.
(Source: ChainCatcher)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments