Skip to main content
See every side of every news story
Published loading...Updated

They Shared Coffee and Code—Then Stole $285 Million in a North Korea–Linked Crypto Hack

Drift said the attackers used fake identities, in-person meetings and at least 3 attack vectors to steal funds, with Mandiant tracing links to UNC4736.

  • On April 1, Drift Protocol suffered a $285 million exploit, describing it as a structured intelligence operation requiring months of preparation by suspected North Korean state-linked actors.
  • Starting in fall 2025, a group posing as a quantitative trading firm infiltrated Drift by meeting contributors at industry events over six months and depositing over $1 million to build trust.
  • Attackers utilized at least three vectors, including a fake TestFlight application, a malicious code repository, and a VSCode and Cursor vulnerability that silently executed arbitrary code without warnings.
  • Security assessments link the incident to the October 2024 Radiant Capital hack, which Mandiant attributed to UNC4736, a North Korean state-affiliated group tracked as AppleJeus or Citrine Sleet.
  • Drift has frozen all remaining functions and removed compromised wallets from its multisig, while urging other teams to treat every device touching a multisig as a potential security target.
Insights by Ground AI

11 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Coin Academy broke the news in on Monday, April 6, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal