Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Seoul Court Rescues Bithumb from Record 6-Month Suspension

May 2, 2026

Bitdeer Sells All Mined BTC This Week: Zero-Holding Strategy Intensifies

May 2, 2026

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»How North Korean spies spent months in-person to drain $285 million from Drift
Security

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026No Comments2 Mins Read

North Korean government-backed hackers are becoming more sophisticated, more precise and now account for more than 76% or nearly $600 million in crypto losses this year alone.

The $285 Drift Protocol exploit, for example, involved what TRMLabs describes as a long and “unprecedented in-person social engineering” attack. It included months of in-person meetings between North Korean proxies and Drift employees.

“North Korean proxies sitting across a table from protocol employees over a period of months. That is, to my knowledge, unprecedented in North Korea’s crypto hacking campaign,” Ari Redbord, Global Head of Policy and Government Affairs at TRMLabs, told CoinDesk. “This is no longer just a remote keyboard operation.”

Ari’s comments accompany TRMLabs’ new report released Thursday, which highlights how North Korea’s two main hacking groups, DPRK and Lazarus, are responsible for 76% of all the crypto losses to hacks and exploits in 2026.

“What we are watching is not a North Korean campaign that is broader — it is one that is sharper,” Redbord said in the report. “North Korea is moving faster and more precisely than ever.”

“North Korea’s cumulative crypto theft now exceeds $6 billion attributed incidents since 2017,” TRM Labs’ report adds.

TRMLabs’ findings coincide with a Wasabi Protocol exploit using a similar playbook to Drift’s April 19 hack, where the assailants used a compromised deployer key with no timelock or multisig to drain $4.5 million.

The $292 million KelpDAO breach exploited a known single-verifier flaw that LayerZero had repeatedly warned against.

The playbook was vastly different from the Drift exploit, according to TRMLabs. Hackers converted the Drift proceeds to USDC, bridged to Ethereum, swapped into ETH, and have not moved them since the day of the theft, which is consistent with the DPRK’s patient, multi-year cashout pattern.

See also  Hackers Target ATM Maker for Bitcoins

In contrast, Lazarus took their KelpDAO proceeds and immediately laundered them through THORChain and Umbra, which is handled almost entirely by Chinese intermediaries operating the well-documented TraderTraitor playbook, the report explains.

The Kelp DAO exploit triggered DeFi’s largest wipeouts as $13 billion exited several lending platforms, most notably, Aave’s, which lost $8.54 billion in deposits over 48 hours, leaving it with a nearly $200 bad-debt crisis, which industry participants are now helping it to alleviate with $300 million in pledges.

Source link

Drain Drift inperson Korean Million months North Spent Spies

Related Posts

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

Moonveil’s $MORE Token Hits All-Time High Amid Ecosystem Momentum

April 21, 2026

Discord and Twitter hacks result in crypto losses of $6m

September 25, 2023

Hoskinson Blasts the XRP Community – Crypto News Bitcoin News

March 30, 2026

Type above and press Enter to search. Press Esc to cancel.