$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
A North Korean state-sponsored group spent six months infiltrating Drift's contributor network through fake trading personas, conference meetups, and malicious code — culminating in a $285 million crypto heist on April 1, 2026.

A shadowy suited figure shakes hands with a glowing holographic crypto trader at a dark international finance conference, with green malicious code cascading across a fragmented blockchain network in the background, symbolizing North Korea's six-month social engineering operation behind the $285 million Drift hack.
A devastating $285 million exploit targeting Drift, a Solana-based decentralized exchange, has been linked to a sophisticated, months-long social engineering campaign orchestrated by a North Korean state-sponsored hacking group known as UNC4736 — also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces. The attack is not an isolated incident. It is the most visible manifestation yet of a threat actor that has spent years refining its techniques against the global financial and digital asset sectors — industries that are expanding rapidly across emerging and high-growth markets worldwide.
The Six-Month Setup
The operation began in fall 2025, when individuals posing as representatives of a quantitative trading firm began approaching Drift contributors at major international cryptocurrency conferences. Over six months, these operatives built convincing professional relationships — complete with fabricated employment histories, public credentials, and verifiable-looking professional networks — before executing the attack on April 1, 2026.
Critically, the individuals who appeared in person were not North Korean nationals. As Drift noted in its post-incident analysis, DPRK threat actors at this operational level are known to deploy third-party intermediaries for face-to-face relationship-building — a tactic that makes conventional due diligence largely ineffective, particularly in international conference environments where high-trust interactions are the norm.
A Telegram group was established at the first conference meeting. What followed were months of technically fluent conversations around trading strategies and vault integrations — interactions entirely consistent with how legitimate trading firms engage with DeFi protocols.
Gaining a Foothold Inside the Ecosystem
Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, depositing over $1 million of their own funds as a calculated trust-building exercise. This gave the threat actors a functioning operational presence inside the Drift ecosystem and continued access to multiple contributors through February and March 2026. During this period, they shared links to projects, tools, and applications they claimed to be developing.
Two primary attack vectors are now suspected:
- Repository-based compromise: One contributor may have cloned a malicious code repository shared by the group. The suspected vector involved a weaponized Microsoft Visual Studio Code project that used the
tasks.jsonfile to automatically trigger malicious code execution upon opening — a technique associated with DPRK's Contagious Interview campaign and one that prompted Microsoft to introduce new security controls in VS Code versions 1.109 and 1.110. - TestFlight-based compromise: A second contributor was persuaded to download a wallet application via Apple's TestFlight under the guise of beta testing.
By the time the April 1 attack was executed, all Telegram chats and associated malicious software had been deleted from compromised devices, significantly complicating forensic recovery efforts.
Attribution and DPRK Connections
Drift attributed the attack with medium confidence to UNC4736, citing both on-chain and operational evidence. On-chain fund flows used to stage and test the operation were traced back to the same actors behind the October 2024 $53 million Radiant Capital hack. Operationally, the personas deployed showed identifiable overlaps with known DPRK-linked activity patterns.
UNC4736 has been active against the cryptocurrency sector since at least 2018 and is best known for the X_TRADER/3CX supply chain breach in 2023 — the first publicly confirmed instance of one software supply chain attack triggering a second, as documented by Mandiant and confirmed by 3CX.
In a January 2026 assessment, CrowdStrike described Golden Chollima as an offshoot of Labyrinth Chollima, primarily targeting small fintech firms across the U.S., Canada, South Korea, India, and Western Europe — operating at a consistent operational tempo to generate baseline revenue for the DPRK regime's military programs, including new destroyers, nuclear-powered submarines, and reconnaissance satellites. The group's willingness to invest months and significant capital — over $1 million in deposited funds in this case alone — before executing an attack signals an adversary with the patience and resources to pursue high-value targets anywhere in the world.
North Korea's Deliberately Fragmented Cyber Apparatus
The Drift hack coincides with broader findings on how DPRK's cyber program has evolved into a deliberately fragmented malware ecosystem — mission-driven, operationally resilient, and specifically structured to slow attribution and frustrate defenders.
The program operates across three distinct tracks:
- Espionage — led by Kimsuky, formally identified by CISA as North Korea's primary intelligence-collection group, targeting government, defense, and research institutions globally
- Revenue generation and sanctions evasion — spearheaded by Lazarus Group, sanctioned by the U.S. Treasury and responsible for the majority of the regime's multi-billion-dollar cryptocurrency theft operations
- Disruptive operations — attributed to Andariel, which CISA and the FBI have formally linked to ransomware and wiper attacks against critical infrastructure, including healthcare and defense sectors
Compartmentalization across tooling, infrastructure, and personnel ensures that exposure in one mission area does not cascade across the broader program — making takedowns of individual actors far less effective than they would be against a more centralized threat group.
The Broader Threat: IT Worker Fraud and Contagious Interview
The Drift operation sits within a much wider DPRK strategy of sustained, large-scale social engineering. Two ongoing campaigns illustrate how deeply this threat has evolved — and how broadly it now reaches.
Contagious Interview is a long-running campaign in which threat actors approach software developers through fake job offers, tricking them into executing malicious code as part of a supposed technical assessment. The campaign has distributed a JavaScript backdoor called DEV#POPPER RAT and an information stealer known as OmniStealer, and has expanded to weaponizing malicious npm packages with over 338 malicious packages and 50,000 cumulative downloads identified to date. In April 2025, the FBI seized the BlockNovas domain — a front company used by the campaign to distribute malware through fraudulent job interviews. The campaign's reach is now global, with victims identified across Europe, South Asia, the Middle East, and Central America.
DPRK IT Worker Fraud is perhaps the most structurally significant element of North Korea's cyber program. Thousands of technically skilled operatives, operating primarily out of China and Russia, are placed into remote roles at companies worldwide using stolen identities, AI-generated personas, and falsified credentials. The U.S. Department of Justice has indicted multiple individuals across multiple enforcement waves, and the FBI has repeatedly warned that once hired, these operatives exfiltrate sensitive data, introduce malware, and in some cases extort employers after being discovered.
Critically for organizations that rely on global talent pipelines, Okta's threat intelligence has confirmed that DPRK IT workers have conducted job interviews with government entities and private companies across the Middle East, with 27% of targeted organizations now lying outside the United States. The scheme's recruitment network has also been documented actively drawing in intermediaries from Iran, Syria, Lebanon, and Saudi Arabia — individuals coached to pass technical interviews and impersonate Western personas on behalf of the regime. This multinational recruitment infrastructure makes the threat significantly harder to attribute and contain.
According to Chainalysis, cryptocurrency is the primary mechanism for routing wages and stolen funds back to Pyongyang while evading international sanctions. In 2025, North Korean hackers stole a record $2.02 billion in cryptocurrency — a 51% year-over-year increase — bringing their estimated all-time total to $6.75 billion. The shift toward fewer, higher-value attacks — exemplified by Drift — reflects a deliberate strategic evolution as global fintech and digital asset markets deepen and expand.
What Security Teams Should Take From This
The Drift breach is a textbook case of what happens when social engineering is treated as a soft risk rather than a technical one. A few specific controls would have materially changed the outcome:
- Third-party vetting at depth — The fake trading firm withstood months of interaction. Standard KYC checks on counterparties are insufficient; continuous behavioral monitoring of integrated third parties is essential
- Developer device and repository hygiene — Cloning an external repository onto a production-adjacent machine should trigger mandatory sandboxing and code review; the VS Code
tasks.jsonattack vector exploits precisely the trust developers extend to workspaces - App sideloading policies — TestFlight and similar platforms bypass app store security reviews; organizations should enforce MDM policies that restrict or monitor sideloaded applications on any device with access to sensitive systems
- Wallet and multisig governance — The attack ultimately succeeded by compromising signers in a multisig configuration; periodic rotation of signers, hardware key enforcement, and time-locked withdrawal policies reduce the blast radius of any single compromise
- Insider threat programs that cover contractors and third parties — As Mandiant's research makes clear, DPRK operators are now targeting the full supply chain of trusted relationships, not just direct employees
For organizations operating in or expanding into fast-growing digital asset markets, the calculus is straightforward: the more valuable the protocol or platform, the more attractive it becomes to a threat actor willing to invest six months of groundwork for a nine-figure return.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.