
Behind the story ⚡ (AI telemetry)Click to expand
See how six named AI agents in the 24markets flow handled intake, verification, writing, review, and visuals for this story. The agents are system roles, not people, journalists, or responsible editors.
Sigrid ⚖️(Intake agent)
Caught the story from «CoinDesk» and cleared it for the desk based on market relevance.
Eskil 🔍(Research agent)
Ran research and cross-checked claims against 1 independent sources.
Ingrid ✍️(Writing agent)
Drafted the article in a clear editorial style, wrote the TL;DR, and structured the body.
Torbjørn ⚖️(Review agent)
“Solid piece — credible sources, clear language, and a strong angle.”
Vidar 📷(Image agent)
Generated the hero image and in-article illustrations.
Prompt: Hero — Wide-angle editorial photograph of a large cryptocurrency conference exhibition floor, taken from slightly above floor level with a 24mm lens. The vast hall is filled with branded booths, standing screens, and clusters of professionals in business attire engaged in conversation. Overhead signage and stage lighting illuminate the scene. The atmosphere is professional but anonymous — no specific faces identifiable. The setting evokes the kind of industry event where undercover agents could blend in undetected. Natural event lighting mixed with warm booth spotlights. No text in image.
Nora ⚡(Publishing agent)
Prepared the story for publication with metadata, sources, and market disclaimer.
An Operation in the Shadow of Crypto Conferences
Drift Protocol, a decentralized exchange built on the Solana blockchain, revealed on Friday that the attack that hit the protocol on April 1 was not a traditional smart contract attack – it was the result of a six-month intelligence operation, according to CoinDesk.
The attackers began preparations as early as October 2025. They posed as representatives of a quantitative trading firm and contacted Drift contributors at major crypto conferences in several countries. The meetings took place face-to-face, lending credibility to the actors and giving them access to key personnel in the project.
To strengthen the illusion of legitimacy, the group went so far as to deposit one million dollars of their own funds into the protocol. Then they waited.
The attackers deposited one million dollars of their own funds and waited for half a year – all to build trust before striking.

Not a Code Error, but Human Failure
The attack did not exploit a vulnerability in Drift's smart contracts. According to Drift's own analyses and data from blockchain security companies like TRM Labs and Elliptic, the attackers combined advanced social engineering with a technical method based on so-called “durable nonces” – a mechanism that allowed them to bypass the protocol's security measures and execute pre-signed transactions.
By compromising devices belonging to Drift contributors – likely through malicious links or tools – they managed to gain administrative control over the protocol's security council and manipulate the multisig structure. Additionally, a fabricated token called CarbonVote Token (CVT) is said to have been used for oracle manipulation.
Solana Foundation President, Lily Liu, subsequently emphasized that the smart contracts themselves held up – the vulnerability lay in the administrative layers surrounding the protocol, not in the code.

Linked to Previous North Korean Attacks
Drift itself states that it links the operation with “medium to high confidence” to the same actors behind the Radiant Capital hack in October 2024 – an incident previously attributed to the North Korean threat group UNC4736, also known as AppleJeus or Citrine Sleet. Blockchain analysts at Elliptic describe “several indicators” pointing to the Democratic People's Republic of Korea (DPRK).
North Korea-affiliated hackers were estimated in 2025 to be behind the theft of over two billion dollars from the crypto sector globally – almost 60 percent of all stolen funds that year, according to available industry data.
Investigation and Response Measures
Following the attack, Drift immediately shut down all deposits and withdrawals and froze the protocol's other functions. The company is now collaborating with security firms such as Mandiant and SEAL 911, as well as law enforcement agencies and crypto exchanges, to track and freeze the stolen funds. Compromised wallets have been removed from the multisig structure.
A preliminary incident report has been published, and Drift has promised a more comprehensive investigation. Crypto lawyer Ariel Givner has, according to CoinDesk, suggested that the incident could be considered civil negligence, given the alleged weaknesses in basic security practices.
The case illustrates a disturbing shift in the attack pattern against the DeFi sector: from exploiting code vulnerabilities to systematically attacking the people and administrative structures behind the protocols.
This article was written using large language models under editorial supervision by Aprex. Content is source-verified and auditable. Read our method →