Cybersecurity — 2026-04-05
TRM Labs and Elliptic Attribute $285M Drift Protocol Hack to North Korean Threat Actors
Security firms TRM Labs and Elliptic attributed the $285 million Drift Protocol exploit to DPRK-linked hackers based on Tornado Cash origins, Pyongyang-time deployment signatures, social engineering patterns, and rapid post-hack laundering. The attack on the Solana-based DeFi exchange used durable nonces to trick multisig signers into pre-signing hidden authorizations, draining funds in 12 minutes on April 1. On-chain staging began March 11, three weeks before execution. Drift sent on-chain messages to four Ethereum wallets holding ~129,000 ETH. If confirmed, this represents the eighteenth DPRK crypto operation tracked this year.
Analysis
Two DPRK operations in a single week, Drift and Axios, confirm North Korea has industrialized crypto theft and supply chain compromise as a revenue and intelligence collection model. The $285M Drift theft alone would fund approximately 18 months of North Korean missile development at estimated program costs.
2 sources
- North Korean Hackers Attack Drift Protocol In USD 285 Million Heist - TRM Labs
- Drift Protocol exploited for $286 million in suspected DPRK-linked attack - Elliptic
View in full brief →