Skip to content
TrackPodcasts
businessApr 4, 20264:41

North Korean Hackers Drain $285 Million From Drift in 10 Seconds

RADIO 007

About this episode

www.osintinvestigate.com
The attackers prepared infrastructure and multiple nonce-based transactions, took over an admin key, and drained five vaults.

Get every episode summarized

Each time RADIO 007 publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

47 searchable segments. Every word is indexed and playable.

North Korean Hackers Drain $285 Million From Drift in 10 Seconds

RADIO 007

0:00
4:41

Full transcript

RADIO 007North Korean Hackers Drain $285 Million From Drift in 10 Seconds. Machine-transcribed; use the interactive transcript above to jump the player to any line.

A North Korean threat actor is likely to be blamed for a $285 million from decentralized finance, defy, platform drift, executed as part of a carefully planned attack. The incident Drift said was a highly sophisticated operation involving the use of durable mounts accounts to pre-sign transactions that delayed execution and the compromise of multi-sig signers approvals. Drift protocol is coordinating with multiple security firms to determine the cause of the incident. Drift is also working with bridges, exchanges, and law enforcement to trace and freeze stolen assets. Drift said promising more details in a future post-mortem. According to Blockchain Security Company Elliptic, the attack was likely mounted by a North Korean threat actor and resulted in a theft of $286 million from Drift. Over the past several years, Pyongyang-aligned hackers are estimated to have stolen over $6.5

billion in cryptocurrency. The attack was executed with extreme precision. The hackers set up supporting infrastructure roughly eight days before, prepared multiple non-space transactions, gained admin control, trained funds from five vaults within seconds, and immediately started laundering them through multiple wallets. A PIF research labs analysis of the high shows that the attackers created a brand new wallet eight days before the exploit, and performed a series of microtransactions to ensure it could receive seven types of tokens. The attackers used the durable knots to create a transaction on the Salana blockchain that would never expire, and then pre-signed every transaction used during the attack to ensure everything was executed rapidly. Five hours before the attack, the hackers gained control of a Drift admin key, which allowed them to modify settings on the protocol. It was protected by a multi-sig, but Drift allows for changes to be approved with only two out of five keyholders.

Five hours before the exploit, the carry-over signer proposed transferring the admin key. One of the new signers co-signed within one second, and because the change had a zero second time lock, it was executed instantly. PIF research labs explains. Fake market, fake tokens, real theft. The hackers used the compromised admin key 25 seconds before the highs to create a fake collateral market for CVT. A worthless token they had minted 20 days earlier, and to disable Drift's safety system that prevents massive, rapid asset drains. The market was configured to drain as many funds as possible by setting CVT parameters to increase the value of the fake tokens, eliminate penalties for depositing massive supply, and eliminate incentives to liquidate the fake position. Additionally, CVT's tier was set to the highest available on Drift to ensure borrowing power for the fake tokens, and an oracle for it was used to increase the value of the worthless tokens to hundreds of millions.

To disable the DeFi platform's anti-drain system, the hackers modified its circuit breakers, which are designed to block withdrawals of too many assets are drained from a vault too fast, raising the value to 500 trillion. The fake market creation and the circuit breaker modifications were bundled into a single on-chain transaction at 16.05 and 39 seconds universal time coordinated. 25 seconds later, the withdrawals began. The entire weaponization took less time than it takes to order coffee, TIF Research Lab's notes. Two seconds after depositing 500 million CVT, which the fake oracle valued at over $100 million, the highs started. Within 10 seconds, funds were drained from JLP, USDC, CBBDC, USDS, DSOL, and WTH. The JLP vault was completely drained. Next, the hackers began laundering the money. The funds were moved from the attackers wallet

to 27 getaway wallets, and then scattered across 57,331 wallet addresses using armated bots. Roughly $225 million in assets were swapped to Ethereum and stored in three wallets. The bots continued their work for over 34 hours, making 590 transactions per minute, operating across multiple blockchains and centralized exchanges simultaneously, adding complexity to the money trail investigation. PIF Research Lab says more than 860,000 transactions were made within 34 hours.

More episodes

More from RADIO 007

View all episodes →