The Drift platform revealed that the April 1, 2026 attack that led to the theft of $285 million was the culmination of a 6-month social engineering operation conducted by the Democratic People’s Republic of Korea (DPRK) that began in the fall of 2025. The Solana-based decentralized exchange described the attack as “ an attack six months in the making ,” attributing it with moderate certainty to the North Korean state-run hacking group UNC4736 .
See also: Drift social engineering: Hackers stole $285 million.

This threat group is also known by the codenames AppleJeus , Citrine Sleet , Golden Chollima , and Gleaming Pisces . It has a history of targeting the cryptocurrency sector for financial theft since at least 2018, most notably the X_TRADER/3CX supply chain attacks in 2023 and the theft of $53 million from DeFi platform Radiant Capital in October 2024.
According to Drift ’s analysis , the connection to North Korea is based on both on-chain and operational evidence. The capital flows used to prepare and test the operation are linked to Radiant attackers and DPRK -linked activity .
Drift's social engineering strategy and UNC4736's tactics
Cybersecurity firm CrowdStrike described Golden Chollima as an offshoot of Labyrinth Chollima that primarily targets cryptocurrency theft, with a focus on small fintech companies in the US, Canada, South Korea, India , and Western Europe. The adversary typically conducts smaller-value thefts at a more consistent operational pace, suggesting responsibility for ensuring key revenue generation for the DPRK.
See also: Social Engineering: The most dangerous “human” virus

Despite improving trade relations with Russia, North Korea needs additional revenue to fund ambitious military plans that include building new destroyers, building nuclear-powered submarines, and launching additional reconnaissance satellites. In at least one incident observed in late 2024, UNC4736 delivered malicious Python packages through a fraudulent recruitment scheme to a European fintech company.
Drift revealed that it was the target of a “ structured intelligence operation ” that required months of planning. Beginning around the fall of 2025, individuals posing as a quantitative trading firm approached Drift associates at a major cryptocurrency conference and international crypto conferences under the guise of protocol integration.
Technical details of the attack and the durable nonce technique
This has been shown to be a deliberate approach, with members of this trading group reaching out and building relationships with specific Drift at various major industry conferences held in multiple countries over a six-month period. The individuals who appeared in person were not North Korean nationals, as DPRK threat actors operating at this level are known to deploy third-party intermediaries to conduct face-to-face relationship building.
The attackers were technically savvy, had verifiable professional backgrounds, and were familiar with how Drift operated. A Telegram group was created upon initial meeting, and months of substantive conversations around trading strategies and potential vault integrations followed. Between December 2025 and January 2026, the team integrated an Ecosystem Vault into Drift , a step that required filling out a form with strategy details.
See also: Social Engineering: The Psychology Behind Attacks

The attack used the durable nonce – prepared, replay-resistant payloads that tricked signers into approving fund transfers to malicious wallets while believing them to be legitimate. The attack emptied 285 million$ from five vaults in 10 seconds via a compromised admin key.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
