FraudHIGH

Drift Loses $285 Million in Social Engineering Attack

Featured image for Drift Loses $285 Million in Social Engineering Attack
THThe Hacker News
DriftNorth Koreasocial engineeringcrypto theftCarbonVote Token
🎯

Basically, Drift lost a lot of money because hackers tricked them into giving away access.

Quick Summary

Drift, a Solana-based decentralized exchange, lost $285 million in a social engineering attack linked to North Korean hackers. This incident highlights the increasing sophistication of crypto theft tactics. Users are urged to monitor their accounts and stay informed about security measures being implemented.

What Happened

On April 1, 2026, Drift, a decentralized exchange built on the Solana blockchain, confirmed a staggering loss of $285 million due to a social engineering attack. The attackers executed a highly sophisticated operation that involved gaining unauthorized access to the Drift Protocol. This was achieved through a novel technique involving durable nonces, which allowed them to pre-sign transactions and delay execution, ultimately leading to a rapid takeover of the platform's administrative powers.

Who's Affected

The attack primarily affects users and investors of Drift, as the stolen funds represent a significant portion of the platform's assets. The incident raises concerns across the decentralized finance (DeFi) community, as it highlights vulnerabilities that can be exploited through social engineering rather than technical flaws in smart contracts or programs.

What Data Was Exposed

While there is no evidence of compromised seed phrases or direct vulnerabilities in Drift's smart contracts, the attackers managed to manipulate transaction approvals. They obtained sufficient multi-signature approvals to execute a malicious admin transfer, which allowed them to introduce a fictitious asset named CarbonVote Token. This token was treated as legitimate collateral worth hundreds of millions, despite being a manufactured asset with minimal initial liquidity.

What You Should Do

For users and investors, the first step is to monitor their accounts closely for any unauthorized transactions. Additionally, users should consider moving their assets to more secure platforms. Drift is currently working with security firms, exchanges, and law enforcement to trace and freeze the stolen assets. Users should stay informed about updates from Drift regarding the incident and any measures being implemented to enhance security.

The Threat

This incident is believed to be linked to North Korean threat actors, who have a history of orchestrating large-scale cryptoasset thefts. Reports from blockchain intelligence firms like Elliptic and TRM Labs indicate that the techniques used in this attack align with patterns previously attributed to North Korean hackers. The attack showcases how social engineering tactics can bypass traditional security measures in decentralized finance.

Tactics & Techniques

The attackers employed a combination of social engineering and technical manipulation to execute their plan. They misled multi-signature signers into pre-signing hidden authorizations, which allowed for a zero-timelock migration of the Security Council, effectively removing the last line of defense for the protocol. This method of attack is a reminder of the evolving landscape of cyber threats in the cryptocurrency space.

Defensive Measures

To safeguard against such attacks, organizations in the crypto space must enhance their security protocols. This includes regular audits of administrative access, educating users about social engineering tactics, and implementing multi-factor authentication wherever possible. The increasing sophistication of these attacks necessitates a proactive approach to security in the rapidly evolving DeFi landscape.

🔒 Pro insight: This incident underscores the necessity for enhanced user education on social engineering, especially in decentralized finance environments.

Original article from

THThe Hacker News
Read Full Article

Related Pings

HIGHFraud

Nigerian Romance Scammer Jailed After Fellow Fraudster Exposed Him

A Nigerian romance scammer has been sentenced to 15 years in prison after being caught by another fraudster. His schemes exploited victims for over $1.5 million. This case underscores the dangers of online scams and the emotional manipulation involved.

Graham Cluley·
CRITICALFraud

North Korean Hackers Drain $285 Million From Drift in Seconds

In a shocking incident, North Korean hackers drained $285 million from the Drift platform in just 10 seconds. This sophisticated attack highlights serious vulnerabilities in DeFi protocols. Drift is now working with security firms to recover the stolen assets.

SecurityWeek·
HIGHFraud

Windows Extortion Plot - Engineer Pleads Guilty to Charges

A former engineer has pleaded guilty to locking Windows admins out of servers in an extortion scheme. This incident underscores the risks of insider threats. Rhyne's actions could lead to a 15-year prison sentence. Companies must strengthen their cybersecurity measures to prevent similar attacks.

BleepingComputer·
HIGHFraud

Drift Protocol - North Korean Hackers Steal $280 Million

North Korean hackers have stolen $280 million from the Drift Protocol by manipulating admin powers. This attack has frozen operations, affecting thousands of traders. Drift is investigating and working to recover the funds.

BleepingComputer·
HIGHFraud

Microsoft Device Code Phishing - EvilTokens Kit Discovered

A global phishing campaign is exploiting Microsoft's device code system using the EvilTokens kit. Organizations are at risk of losing sensitive data as attackers gain access to accounts. Vigilance and security measures are crucial to thwart these threats.

SC Media·
HIGHFraud

Drift Protocol - $285 Million Lost in Major Crypto Heist

Drift Protocol has lost an estimated $285 million in a major crypto heist linked to an exposed private key. All transactions are suspended as investigations proceed. This incident underscores the vulnerabilities in decentralized finance platforms.

SC Media·