{
    "id": 68005,
    "date": "2026-04-06T08:41:47",
    "date_gmt": "2026-04-06T01:41:47",
    "guid": {
        "rendered": "https:\/\/hbbgroup.net\/crypto-attorney-says-drift-incident-may-qualify-as-civil-negligence\/"
    },
    "modified": "2026-04-06T08:41:47",
    "modified_gmt": "2026-04-06T01:41:47",
    "slug": "crypto-attorney-says-drift-incident-may-qualify-as-civil-negligence",
    "status": "publish",
    "type": "post",
    "link": "https:\/\/hbbgroup.net\/en_us\/crypto-attorney-says-drift-incident-may-qualify-as-civil-negligence\/",
    "title": {
        "rendered": "Crypto attorney says Drift incident may qualify as &#8216;civil negligence&#8217;"
    },
    "content": {
        "rendered": "<div data-testid=\"html-renderer-container\">\n<p>The hack of the Solana-based decentralized finance (DeFi) platform Drift Protocol could have been prevented if standard operational security procedures were followed by the Drift team, and may constitute \u201ccivil negligence,\u201d according to attorney Ariel Givner.<\/p>\n<p>\u201cIn plain terms, civil negligence means they failed their basic duty to protect the money they were managing,\u201d Givner <a title=\"https:\/\/x.com\/GivnerAriel\/status\/2040807239259128209\" href=\"https:\/\/x.com\/GivnerAriel\/status\/2040807239259128209\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> in response to the post-mortem <a title=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409\" href=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409\" target=\"_blank\" rel=\"nofollow noopener\">update<\/a> provided by the Drift team and how it handled Wednesday\u2019s <a title=\"https:\/\/cointelegraph.com\/news\/drift-protocol-pause-deposit-unusual-activity\" href=\"https:\/\/cointelegraph.com\/news\/drift-protocol-pause-deposit-unusual-activity\">$280 million exploit<\/a>.<\/p>\n<p>The Drift team failed to follow \u201cbasic\u201d security procedures, including keeping signing keys on separate, \u201cair-gapped\u201d systems that are never used for developer work, and conducting due diligence on blockchain developers met through industry conferences.<\/p>\n<figure><img decoding=\"async\" alt=\"Cybercrime, North Korea, Cybersecurity, Hacks, Lazarus Group\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2026-04\/019d5f7b-c3df-79ef-be0b-5777981621e5.png\"><figcaption><em>Source: <\/em><a title=\"https:\/\/x.com\/GivnerAriel\/status\/2040782131178115482\" href=\"https:\/\/x.com\/GivnerAriel\/status\/2040782131178115482\" target=\"_blank\" rel=\"nofollow noopener\"><em>Ariel Givner<\/em><\/a><\/figcaption><\/figure>\n<p>\u201cEvery serious project knows this. Drift didn\u2019t follow it,\u201d she said, adding, \u201cThey knew crypto is full of hackers, especially North Korean state teams.\u201d Givner continued:\u00a0<\/p>\n<blockquote><p>\u201cYet their team spent months chatting on Telegram, meeting strangers at conferences, opening sketchy code repos, and downloading fake apps on devices tied to multisignature controls.\u201d<\/p><\/blockquote>\n<p>Advertisements for class action lawsuits against Drift Protocol are already circulating, she <a title=\"https:\/\/x.com\/GivnerAriel\/status\/2040809488333041923\" href=\"https:\/\/x.com\/GivnerAriel\/status\/2040809488333041923\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a>. Cointelegraph reached out to the Drift Team but did not receive a response by the time of publication.<\/p>\n<figure><img decoding=\"async\" alt=\"Cybercrime, North Korea, Cybersecurity, Hacks, Lazarus Group\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2026-04\/019d5f7c-c8ae-7ee1-bbb6-24ab077f77c0.png\"><figcaption><em>Source: <\/em><a title=\"https:\/\/x.com\/GivnerAriel\/status\/2040809488333041923\" href=\"https:\/\/x.com\/GivnerAriel\/status\/2040809488333041923\" target=\"_blank\" rel=\"nofollow noopener\"><em>Ariel Givner<\/em><\/a><\/figcaption><\/figure>\n<p>The incident is a reminder that social engineering and <a title=\"https:\/\/cointelegraph.com\/news\/north-korean-it-workers-charged-crypto-theft\" href=\"https:\/\/cointelegraph.com\/news\/north-korean-it-workers-charged-crypto-theft\">project infiltration by malicious actors <\/a>are major attack vectors for cryptocurrency developers that could drain user funds and permanently erode customer trust in compromised platforms.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a title=\"https:\/\/cointelegraph.com\/news\/drift-280-million-hack-questions-circle-response\" href=\"https:\/\/cointelegraph.com\/news\/drift-280-million-hack-questions-circle-response\"><em><strong>Drift explains $280M exploit as critics question Circle over USDC freeze<\/strong><\/em><\/a><\/p>\n<h2>Drift Protocol says attack took \u201cmonths\u201d of planning<\/h2>\n<p>The Drift Protocol team published an update on Saturday outlining how the exploit occurred and claimed that the attackers <a title=\"https:\/\/cointelegraph.com\/news\/drift-protocol-exploit-preparation-preliminary-findings\" href=\"https:\/\/cointelegraph.com\/news\/drift-protocol-exploit-preparation-preliminary-findings\">planned the attack for six months<\/a> before execution.<\/p>\n<p>Threat actors first approached the Drift team at a \u201cmajor\u201d crypto industry conference in October 2025, expressing interest in protocol integrations and collaboration.<\/p>\n<div>\n<p>The malicious actors continued to build rapport with the Drift development team in the ensuing six months, and once enough trust was built, they began sending the Drift team malicious links and embedding malware that compromised developer machines.<\/p>\n<p>These individuals, who are suspected of working for North Korea state-affiliated hackers and physically approached the Drift developers, were not North Korean nationals, according to the Drift team.<\/p>\n<\/div>\n<p>Drift <a title=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409?s=20\" href=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409?s=20\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a>, with \u201cmedium-high confidence,\u201d that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.<\/p>\n<p>In December 2024, Radiant Capital\u00a0<a title=\"https:\/\/cointelegraph.com\/news\/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack\" href=\"https:\/\/cointelegraph.com\/news\/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack\">said the exploit<\/a>\u00a0was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor.\u00a0<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a title=\"https:\/\/cointelegraph-magazine.com\/hackers-crypto-wallets-recover-savings\/\" href=\"https:\/\/cointelegraph-magazine.com\/hackers-crypto-wallets-recover-savings\/\" target=\"_blank\" rel=\"nofollow noopener\"><em><strong>Meet the hackers who can help get your crypto life savings back<\/strong><\/em><\/a><\/p>\n<p><template data-type=\"defi_newsletter\" data-name=\"subscription_form\" data-label=\"Subscription Form: DeFi Newsletter\"><\/template><\/div>\n<p>Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph\u2019s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy <a href=\"http:\/\/cointelegraph.com\/editorial-policy\">https:\/\/cointelegraph.com\/editorial-policy<\/a><\/p>",
        "protected": false
    },
    "excerpt": {
        "rendered": "<p>The hack of the Solana-based decentralized finance (DeFi) platform Drift Protocol could have been prevented if standard operational security procedures [&hellip;]<\/p>",
        "protected": false
    },
    "author": 5,
    "featured_media": 68007,
    "comment_status": "open",
    "ping_status": "open",
    "sticky": false,
    "template": "",
    "format": "standard",
    "meta": {
        "_acf_changed": false,
        "footnotes": ""
    },
    "categories": [
        220
    ],
    "tags": [],
    "class_list": [
        "post-68005",
        "post",
        "type-post",
        "status-publish",
        "format-standard",
        "has-post-thumbnail",
        "hentry",
        "category-tien-dien-tu"
    ],
    "acf": [],
    "_links": {
        "self": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/68005",
                "targetHints": {
                    "allow": [
                        "GET"
                    ]
                }
            }
        ],
        "collection": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts"
            }
        ],
        "about": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/types\/post"
            }
        ],
        "author": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/users\/5"
            }
        ],
        "replies": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/comments?post=68005"
            }
        ],
        "version-history": [
            {
                "count": 0,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/68005\/revisions"
            }
        ],
        "wp:featuredmedia": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media\/68007"
            }
        ],
        "wp:attachment": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media?parent=68005"
            }
        ],
        "wp:term": [
            {
                "taxonomy": "category",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/categories?post=68005"
            },
            {
                "taxonomy": "post_tag",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/tags?post=68005"
            }
        ],
        "curies": [
            {
                "name": "wp",
                "href": "https:\/\/api.w.org\/{rel}",
                "templated": true
            }
        ]
    }
}