• bitcoinBitcoin (BTC) $ 67,306.00
  • ethereumEthereum (ETH) $ 2,054.08
  • tetherTether (USDT) $ 0.999788
  • bnbBNB (BNB) $ 592.85
  • xrpXRP (XRP) $ 1.30
  • usd-coinUSDC (USDC) $ 1.00
  • solanaSolana (SOL) $ 79.66
  • tronTRON (TRX) $ 0.318857
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.090673
  • usdsUSDS (USDS) $ 0.999830
  • whitebitWhiteBIT Coin (WBT) $ 51.20
  • leo-tokenLEO Token (LEO) $ 10.16
  • cardanoCardano (ADA) $ 0.243319
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • hyperliquidHyperliquid (HYPE) $ 35.60
  • bitcoin-cashBitcoin Cash (BCH) $ 421.85
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 8.61
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 330.96
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.999517
  • canton-networkCanton (CC) $ 0.139811
  • stellarStellar (XLM) $ 0.159044
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • daiDai (DAI) $ 0.999976
  • usd1-wlfiUSD1 (USD1) $ 0.999374
  • susdssUSDS (SUSDS) $ 1.08
  • memecoreMemeCore (M) $ 2.50
  • litecoinLitecoin (LTC) $ 53.27
  • zcashZcash (ZEC) $ 242.43
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999893
  • avalanche-2Avalanche (AVAX) $ 8.88
  • hedera-hashgraphHedera (HBAR) $ 0.086926
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • suiSui (SUI) $ 0.850838
  • rainRain (RAIN) $ 0.006626
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.25
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.097781
  • crypto-com-chainCronos (CRO) $ 0.069257
  • bittensorBittensor (TAO) $ 298.08
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,620.88
  • pax-goldPAX Gold (PAXG) $ 4,630.84
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.664831
  • polkadotPolkadot (DOT) $ 1.23
  • uniswapUniswap (UNI) $ 3.11
  • global-dollarGlobal Dollar (USDG) $ 0.999973
  • falcon-financeFalcon USD (USDF) $ 0.998412
  • okbOKB (OKB) $ 82.30
  • pi-networkPi Network (PI) $ 0.169959
  • skySky (SKY) $ 0.074194
  • aster-2Aster (ASTER) $ 0.662365
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • nearNEAR Protocol (NEAR) $ 1.25
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • htx-daoHTX DAO (HTX) $ 0.000002
  • usddUSDD (USDD) $ 0.999955
  • pepePepe (PEPE) $ 0.000003
  • aaveAave (AAVE) $ 91.65
  • ripple-usdRipple USD (RLUSD) $ 0.999958
  • ethereum-classicEthereum Classic (ETC) $ 8.58
  • bfusdBFUSD (BFUSD) $ 0.999599
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • bitget-tokenBitget Token (BGB) $ 1.85
  • internet-computerInternet Computer (ICP) $ 2.27
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ondo-financeOndo (ONDO) $ 0.250658
  • gatechain-tokenGate (GT) $ 6.46
  • quant-networkQuant (QNT) $ 75.26
  • kucoin-sharesKuCoin (KCS) $ 8.02
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • algorandAlgorand (ALGO) $ 0.119077
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.04
  • pump-funPump.fun (PUMP) $ 0.001651
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.090450
  • render-tokenRender (RENDER) $ 1.85
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • usdtbUSDtb (USDTB) $ 0.998874
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • cosmosCosmos Hub (ATOM) $ 1.68
  • kaspaKaspa (KAS) $ 0.030906
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • nexoNEXO (NEXO) $ 0.838167
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • worldcoin-wldWorldcoin (WLD) $ 0.249372
  • morphoMorpho (MORPHO) $ 1.46
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • midnight-3Midnight (NIGHT) $ 0.041355
  • ethenaEthena (ENA) $ 0.077347
  • wbnbWrapped BNB (WBNB) $ 759.61
  • ousgOUSG (OUSG) $ 114.79
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.839258
  • official-trumpOfficial Trump (TRUMP) $ 2.84
  • vechainVeChain (VET) $ 0.007495
  • flare-networksFlare (FLR) $ 0.007442
  • filecoinFilecoin (FIL) $ 0.825252
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • yldsYLDS (YLDS) $ 0.999999
  • beldexBeldex (BDX) $ 0.079812
  • xdce-crowd-saleXDC Network (XDC) $ 0.030947
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • hash-2Provenance Blockchain (HASH) $ 0.010880
  • ghoGHO (GHO) $ 0.999465
  • stable-2​​Stable (STABLE) $ 0.026731
  • jupiter-exchange-solanaJupiter (JUP) $ 0.158820
  • justJUST (JST) $ 0.063344
  • usual-usdUsual USD (USD0) $ 0.999126
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • arbitrumArbitrum (ARB) $ 0.091126
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.229333
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • true-usdTrueUSD (TUSD) $ 0.999410
  • a7a5A7A5 (A7A5) $ 0.012416
  • bonkBonk (BONK) $ 0.000005
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.40
  • layerzeroLayerZero (ZRO) $ 1.82
  • dexeDeXe (DEXE) $ 8.89
  • euro-coinEURC (EURC) $ 1.15
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.615860
  • siren-2Siren (SIREN) $ 0.554405
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • chilizChiliz (CHZ) $ 0.038401
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998685
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006115
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • blockstackStacks (STX) $ 0.209113
  • dashDash (DASH) $ 30.19
  • hastra-primePRIME (PRIME) $ 1.03
  • tezosTezos (XTZ) $ 0.340237
  • usxUSX (USX) $ 0.999671
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • adi-tokenADI (ADI) $ 4.43
  • kinesis-goldKinesis Gold (KAU) $ 147.60
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • sei-networkSei (SEI) $ 0.052099
  • ether-fiEther.fi (ETHFI) $ 0.443604
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • decredDecred (DCR) $ 19.84
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • sun-tokenSun Token (SUN) $ 0.017359
  • cocaCOCA (COCA) $ 1.30
  • venice-tokenVenice Token (VVV) $ 7.29
  • apenftAINFT (NFT) $ 0.00000033
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • bitcoin-svBitcoin SV (BSV) $ 16.10
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • edgexedgeX (EDGE) $ 0.919642
  • gnosisGnosis (GNO) $ 118.56
  • curve-dao-tokenCurve DAO (CRV) $ 0.209983
  • bittorrentBitTorrent (BTT) $ 0.00000031
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • usdaiUSDai (USDAI) $ 0.999933
  • monadMonad (MON) $ 0.027294
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • aerodrome-financeAerodrome Finance (AERO) $ 0.312336
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • doublezeroDoubleZero (2Z) $ 0.082961
  • injective-protocolInjective (INJ) $ 2.77
  • fraxLegacy Frax Dollar (FRAX) $ 0.994051
  • kaiaKaia (KAIA) $ 0.046479
  • plasmaPlasma (XPL) $ 0.115403
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • official-foOfficial FO (FO) $ 0.268668
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • crvusdcrvUSD (CRVUSD) $ 0.997321
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • zebec-networkZebec Network (ZBCN) $ 0.002680
  • lido-daoLido DAO (LDO) $ 0.308666
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • conflux-tokenConflux (CFX) $ 0.050474
  • kinesis-silverKinesis Silver (KAG) $ 69.30
  • jasmycoinJasmyCoin (JASMY) $ 0.005208
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • flokiFLOKI (FLOKI) $ 0.000027
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • celestiaCelestia (TIA) $ 0.284144
  • iotaIOTA (IOTA) $ 0.058517
  • the-graphThe Graph (GRT) $ 0.023549
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • kite-2Kite (KITE) $ 0.140412
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • olympusOlympus (OHM) $ 15.94

Drift says $270 million exploit was a six-month North Korean intelligence operation

0 3

Drift says $270 million exploit was a six-month North Korean intelligence operation

A six-month intelligence operation preceded the $270 million exploit of Drift Protocol and was carried out by a North Korean state-affiliated group, according to a detailed incident update published by the team earlier on Sunday.

The attackers first made contact around fall 2025 at a major crypto conference, presenting themselves as a quantitative trading firm looking to integrate with Drift.

They were technically fluent, had verifiable professional backgrounds, and understood how the protocol operated, Drift said. A Telegram group was established and what followed were months of substantive conversations around trading strategies and vault integrations, interactions that are standard for how trading firms onboard with DeFi protocols.

Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, held multiple working sessions with contributors, deposited over $1 million of their own capital, and built a functioning operational presence inside the ecosystem.

Drift contributors met individuals from the group face to face at multiple major industry conferences across several countries through February and March. By the time the attack launched on April 1, the relationship was nearly half a year old.

The compromise appears to have come through two vectors.

A second downloaded a TestFlight application, Apple’s platform for distributing pre-release apps that bypasses App Store security review, which the group presented as their wallet product.

For the repository vector, Drift pointed to a known vulnerability in VSCode and Cursor, two of the most widely used code editors in software development, that the security community had been flagging since late 2025, where simply opening a file or folder in the editor was sufficient to silently execute arbitrary code with no prompt or warning of any kind.

Once devices were compromised, the attackers had what they needed to obtain the two multisig approvals that enabled the durable nonce attack CoinDesk detailed earlier this week. Those pre-signed transactions sat dormant for more than a week before being executed on April 1, draining $270 million from the protocol’s vaults in under a minute.

The attribution points to UNC4736, a North Korean state-affiliated group also tracked as AppleJeus or Citrine Sleet, based on both on-chain fund flows tracing back to the Radiant Capital attackers and operational overlap with known DPRK-linked personas.

The individuals who appeared in person at conferences were not North Korean nationals, however. DPRK threat actors at this level are known to deploy third-party intermediaries with fully constructed identities, employment histories, and professional networks built to withstand due diligence.

Drift urged other protocols to audit access controls and treat every device touching a multisig as a potential target. The broader implication is uncomfortable for an industry that relies on multisig governance as its primary security model.

But if attackers are willing to spend six months and a million dollars building a legitimate presence inside an ecosystem, meet teams in person, contribute real capital, and wait, the question is what security model is designed to catch that.

Source

Leave A Reply

Your email address will not be published.