{
    "id": 68181,
    "date": "2026-04-06T08:44:13",
    "date_gmt": "2026-04-06T01:44:13",
    "guid": {
        "rendered": "https:\/\/hbbgroup.net\/drift-protocol-says-280m-exploit-took-months-of-deliberate-preparation\/"
    },
    "modified": "2026-04-06T08:44:13",
    "modified_gmt": "2026-04-06T01:44:13",
    "slug": "drift-protocol-says-280m-exploit-took-months-of-deliberate-preparation",
    "status": "publish",
    "type": "post",
    "link": "https:\/\/hbbgroup.net\/en_us\/drift-protocol-says-280m-exploit-took-months-of-deliberate-preparation\/",
    "title": {
        "rendered": "Drift Protocol says $280M exploit took &#8216;months of deliberate preparation&#8217;"
    },
    "content": {
        "rendered": "<div data-testid=\"html-renderer-container\">\n<p>Drift Protocol, the decentralized exchange (DEX) that lost an estimated $280 million in an exploit last week, claims the loss was the result of a six-month, highly coordinated attack.<\/p>\n<p>\u201cThe preliminary investigation shows that Drift experienced a structured intelligence operation requiring organizational backing, significant resources, and months of deliberate preparation,\u201d Drift <a title=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409?s=20\" href=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409?s=20\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> in an X post on Saturday.<\/p>\n<h2>Attack began at a \u201cmajor crypto conference\u201d<\/h2>\n<p>According to Drift, the attack can be traced back to around October 2025, when malicious actors posing as a quantitative trading firm first approached Drift contributors at a \u201cmajor crypto conference,\u201d claiming to be interested in integrating with the protocol.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2026-04\/019d5c61-48cd-72af-8478-719d1bec43c7.png\"><figcaption><em>Source: <\/em><a title=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409?s=20\" href=\"https:\/\/x.com\/DriftProtocol\/status\/2040611161121370409?s=20\" target=\"_blank\" rel=\"nofollow noopener\"><em>Drift Protocol<\/em><\/a><\/figcaption><\/figure>\n<p>The group continued to engage contributors in person at multiple industry events over a six-month period. \u201cIt is now understood that this appears to be a targeted approach, where individuals from this group continued to deliberately seek out and engage specific Drift contributors,\u201d Drift said.<\/p>\n<p>\u201cThey were technically fluent, had verifiable professional backgrounds, and were familiar with how Drift operated,\u201d Drift said.<\/p>\n<p>After gaining trust and access to Drift Protocol over six months, they used shared malicious links and tools to compromise contributors\u2019 devices, execute the exploit, and then wiped their presence immediately after the attack.<\/p>\n<p>The incident serves as a reminder for crypto industry participants to remain cautious and skeptical, even during in-person interactions, as crypto conferences can be prime targets for sophisticated threat actors.<\/p>\n<h2>Drift flags a high probability of a Radiant Capital hack link<\/h2>\n<p>Drift said, with \u201cmedium-high confidence,\u201d that the exploit was carried out by the same actors behind the October 2024 Radiant Capital hack.<\/p>\n<p>In December 2024, Radiant Capital <a title=\"https:\/\/cointelegraph.com\/news\/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack\" href=\"https:\/\/cointelegraph.com\/news\/radiant-capital-north-korean-impersonated-ex-contractor-50-million-hack\">said the exploit<\/a> was carried out through malware sent via Telegram from a North Korea-aligned hacker posing as an ex-contractor.\u00a0<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2026-04\/019d5c62-f53f-74e0-aefb-3ef3b1d2de5b.png\"><figcaption><em>Source: <\/em><a title=\"https:\/\/x.com\/0xDith\/status\/2040633360872280216?s=20\" href=\"https:\/\/x.com\/0xDith\/status\/2040633360872280216?s=20\" target=\"_blank\" rel=\"nofollow noopener\"><em>Dith<\/em><\/a><\/figcaption><\/figure>\n<p>\u201cThis ZIP file, when shared for feedback among other developers, ultimately delivered malware that facilitated the subsequent intrusion,\u201d Radiant Capital said.<\/p>\n<p>Drift said that the individuals who appeared in person \u201cwere not North Korean nationals.\u201d<\/p>\n<p><em><strong>Related: <\/strong><\/em><a title=\"https:\/\/cointelegraph.com\/news\/naoris-post-quantum-blockchain-quantum-security-risks-gain-attention\" href=\"https:\/\/cointelegraph.com\/news\/naoris-post-quantum-blockchain-quantum-security-risks-gain-attention\"><em><strong>Naoris launches post-quantum blockchain as quantum security risks gain attention<\/strong><\/em><\/a><\/p>\n<p>\u201cDPRK threat actors operating at this level are known to deploy third-party intermediaries to conduct face-to-face relationship-building,\u201d Drift said.<\/p>\n<p>Drift said that it is working with law enforcement and others in the crypto industry to \u201cbuild a complete picture of what happened during the April 1st attack.\u201d<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a title=\"https:\/\/cointelegraph-magazine.com\/bitcoin-price-speculation-us-clarity-act-compromise-coinbase-hodlers-digest\/\" href=\"https:\/\/cointelegraph-magazine.com\/bitcoin-price-speculation-us-clarity-act-compromise-coinbase-hodlers-digest\/\" target=\"_blank\" rel=\"nofollow noopener\"><em><strong>Bitcoin 85% crashes \u2018done,\u2019 CLARITY Act speculation mounts: Hodler\u2019s Digest, Mar. 29 \u2013 April 4<\/strong><\/em><\/a><\/p>\n<p><template data-type=\"crypto_biz\" data-name=\"subscription_form\" data-label=\"Subscription Form: Crypto Biz Newsletter\"><\/template><\/div>\n<p>Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph\u2019s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy <a href=\"http:\/\/cointelegraph.com\/editorial-policy\">https:\/\/cointelegraph.com\/editorial-policy<\/a><\/p>",
        "protected": false
    },
    "excerpt": {
        "rendered": "<p>Drift Protocol, the decentralized exchange (DEX) that lost an estimated $280 million in an exploit last week, claims the loss [&hellip;]<\/p>",
        "protected": false
    },
    "author": 5,
    "featured_media": 68182,
    "comment_status": "open",
    "ping_status": "open",
    "sticky": false,
    "template": "",
    "format": "standard",
    "meta": {
        "_acf_changed": false,
        "footnotes": ""
    },
    "categories": [
        220
    ],
    "tags": [],
    "class_list": [
        "post-68181",
        "post",
        "type-post",
        "status-publish",
        "format-standard",
        "has-post-thumbnail",
        "hentry",
        "category-tien-dien-tu"
    ],
    "acf": [],
    "_links": {
        "self": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/68181",
                "targetHints": {
                    "allow": [
                        "GET"
                    ]
                }
            }
        ],
        "collection": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts"
            }
        ],
        "about": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/types\/post"
            }
        ],
        "author": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/users\/5"
            }
        ],
        "replies": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/comments?post=68181"
            }
        ],
        "version-history": [
            {
                "count": 0,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/68181\/revisions"
            }
        ],
        "wp:featuredmedia": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media\/68182"
            }
        ],
        "wp:attachment": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media?parent=68181"
            }
        ],
        "wp:term": [
            {
                "taxonomy": "category",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/categories?post=68181"
            },
            {
                "taxonomy": "post_tag",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/tags?post=68181"
            }
        ],
        "curies": [
            {
                "name": "wp",
                "href": "https:\/\/api.w.org\/{rel}",
                "templated": true
            }
        ]
    }
}