Skip to content

North Korea Executes $270 Million Cyber Heist

$270 Million Drift Protocol Exploit Linked to North Korean Operation

  • The $270 million exploit of Drift Protocol was executed on April 1, following a six-month intelligence operation.
  • Attackers, identified as UNC4736 (a North Korean state-affiliated group), initially engaged with Drift at a crypto conference in fall.
  • They deposited over $1 million and established a presence within the ecosystem before the attack.
  • The breach exploited vulnerabilities in VSCode and Cursor, allowing attackers to execute arbitrary code without warning.
  • Pre-signed transactions were used to drain funds from the protocol’s vaults in under a minute after remaining dormant for over a week.

Drift Protocol’s incident highlights significant security concerns within DeFi ecosystems, especially regarding multisig governance models. The attackers’ extensive preparation underscores the need for enhanced security measures across protocols.

The exploit demonstrates vulnerabilities that can be targeted by sophisticated actors, as evidenced by the $270 million loss from Drift Protocol’s vaults due to prolonged infiltration efforts.(Source)

Share