Drift hacking causes $280 million in losses… “A coordinated attack prepared over six months, linked to a North Korea-affiliated group”
Summary
- Drift said the roughly $280 million hack was a coordinated operation prepared over about six months.
- The attacker reportedly posed as a legitimate user, deposited more than $1 million, and secured an internal access path.
- Drift said the incident was this year’s largest DeFi hack and the second-largest security breach in the Solana ecosystem on record.
Forecast Trend Report by Period



The hacking incident at Solana-based derivatives exchange Drift has raised the possibility that it was a long-term infiltration operation carried out by a North Korea-linked group.
According to The Block on the 5th (local time), Drift said the roughly $280 million hack that occurred on the 1st was a coordinated operation prepared over about six months. The attacker reportedly approached a trading firm by posing as one at a global event in the second half of 2025, then built internal trust through subsequent offline meetings and collaboration.
They were said to have onboarded onto the platform like legitimate users, deposited more than $1 million, and participated in collaborative processes—steps believed to have helped them secure an internal access path.
The attack method combined social engineering with system vulnerabilities rather than exploiting a smart-contract flaw. Signs suggest the attacker compromised developers’ devices by gaining access to a repository containing malicious code or inducing installation of a TestFlight-based application.
The attacker then reportedly used Solana (SOL)’s “durable nonce” feature to seize administrator privileges based on previously obtained multi-signature approval authority and withdraw funds within a short period.
Based on on-chain fund flows and attack patterns, Drift assessed that this incident is highly likely the work of the same North Korea-linked group behind the 2024 Radiant Capital hack. However, the individuals who made direct contact were believed to have used third parties, indicating a sophisticated approach combining identity masking with offline networks.
Drift is currently taking response measures, including suspending protocol functions and removing compromised wallets. The incident was the largest DeFi hack this year and was recorded as the second-largest security breach ever within the Solana ecosystem.

Suehyeon Lee
shlee@bloomingbit.ioI'm reporter Suehyeon Lee, your Web3 Moderator.


![[Key Economic & Crypto Events Today] US March ISM Non-Manufacturing PMI, etc.](https://media.bloomingbit.io/static/news/brief_en.webp?w=250)
![[Market] Bitcoin regains $69,000 level…extends gains after Trump ultimatum](https://media.bloomingbit.io/PROD/news/fb5c80e1-f032-4078-854d-6b6c4c217ab5.webp?w=250)
![[Market] Bitcoin regains the $68,000 level…major altcoins trade mixed](https://media.bloomingbit.io/PROD/news/70519d37-b0ef-4525-a98a-fec781d9405e.webp?w=250)
