North Korean Hackers Infiltrate Drift Protocol in $270M Crypto Heist
North Korean state-linked hackers conducted a sophisticated six-month infiltration of Drift Protocol, culminating in a $270 million theft on April 1. The attackers, identified as UNC4736 (AppleJeus/Citrine Sleet), posed as a quantitative trading firm, building trust through in-person meetings at global crypto conferences and depositing over $1 million in legitimate funds.
The operation exploited a fake TestFlight app and a known VSCode/Cursor vulnerability to compromise systems. Legal experts suggest the breach may constitute civil negligence, with class action preparations already underway.
This attack demonstrates a concerning evolution in crypto-targeted espionage - replacing smash-and-grab tactics with long-term relationship building. The hackers' deep technical fluency and verifiable professional personas enabled unprecedented access.
Related Articles
Log in to Reply
Log in to comment your thoughtsComments