Drift Protocol Says April 1 Attack Linked to North Korea-Backed Hacker Group UNC4736
Drift Protocol said in a post on X that its preliminary review of the April 1, 2026, attack points to UNC4736, a North Korean state-sponsored hacking group also tracked as AppleJeus or Citrine Sleet.
According to Drift, the attackers spent roughly six months cultivating access starting in fall 2025, using in-person approaches through intermediaries at crypto conferences and setting up fake quantitative trading firms. The effort ultimately led contributors to download malicious code libraries or applications.
Drift said it has frozen all protocol functions and removed compromised wallets from its multisignature configuration. Mandiant has been brought in to run an in-depth forensic investigation.
The investigation also found that on-chain funds used to test the operation can be traced to the same actors behind the October 2024 Radiant Capital breach.