NewsCryptoDrift Protocol Hacker Resumes Moving $285M in Stolen Funds After Four Months of Silence

Drift Protocol Hacker Resumes Moving $285M in Stolen Funds After Four Months of Silence

Author: Cryptopolitan·

Key Takeaways

  • •An Ethereum wallet associated with the Drift Protocol exploit moved approximately 23,095 ETH valued at $44.4 million through Tornado Cash, representing the first significant movement of stolen funds in four months.
  • •The $285 million theft was accomplished through a prolonged social engineering operation in which attackers impersonated quantitative trading firm representatives for six months before compromising developers' devices.
  • •Multiple blockchain analytics firms have linked the exploit to North Korean state-sponsored hackers, consistent with documented DPRK patterns of keeping stolen assets dormant before using mixers and bridges to obstruct tracing.
  • •At least 20 Solana-based projects experienced disruptions due to their reliance on Drift's vault structure as a yield source, highlighting systemic concentration risk within the ecosystem.
  • •Approximately $240 million of the original $285 million stolen remains unaccounted for relative to this latest batch of transfers, with analysts expecting further movement of assets in the coming days.
Drift Protocol Hacker Resumes Moving $285M in Stolen Funds After Four Months of Silence

An Ethereum wallet labeled "Drift Exploiter 4" on Etherscan has begun transferring funds tied to the April hack of Drift Protocol, which resulted in the loss of approximately $285 million — placing it among the largest cryptocurrency thefts on record.

According to blockchain security firm PeckShield, an address associated with the Drift exploiter transferred roughly $44.4 million — equivalent to 23,095.1 ETH — to Tornado Cash, along with a separate transfer of 0.85 ETH to Bybit. The wallet, identified as 0xbDdAE987FEe930910fCC5aa403D5688fB440561B, shows the Tornado Cash deposits were split across multiple transactions. The same address is part of Arkham Intelligence's "Drift Protocol Exploiter" cluster, which includes nearly twenty wallets suspected of involvement in the exploit.

These transactions mark the first substantial movement of the stolen funds in four months. While investigators have not issued a definitive attribution, several blockchain analytics firms have linked the operation to North Korean state-sponsored hackers or infrastructure associated with prior DPRK-linked activities. United Nations sanctions monitors and the FBI have previously documented North Korea's use of cryptocurrency theft as a significant revenue source for the sanctions-bound regime, with estimated cumulative proceeds running into billions of dollars in recent years.

Funds Resume Moving After Months of Inactivity

Drift, the largest perpetual futures trading platform on Solana, suffered the $285 million loss after attackers compromised the protocol through means that did not involve a smart contract vulnerability. PeckShield reported that the incident cut Drift's total value locked by more than 50% and enabled the attackers to rapidly bridge the bulk of the stolen assets from Solana to Ethereum before ceasing activity.

The latest transfers are consistent with laundering patterns documented by blockchain investigators. Chainalysis' 2026 Crypto Crime Report notes that groups connected to North Korea typically keep stolen assets dormant for extended periods before employing bridges, wallets, and privacy tools to move funds and hinder recovery efforts.

Routing funds through Tornado Cash also follows a well-documented approach. The mixer has been under U.S. sanctions since 2022, yet investigators report it remains widely used to sever the link between deposits and withdrawals. The persistence of Tornado Cash usage despite sanctions underscores the broader enforcement challenge posed by decentralized, non-custodial protocols that lack a central operator to compel compliance. Nevertheless, firms such as Chainalysis and Elliptic maintain that wallet clustering and cross-chain analysis can still help trace portions of these transactions.

The separate 0.85 ETH transfer to Bybit may represent a small test transaction preceding larger cash-out attempts, a technique commonly observed in laundering operations where attackers verify that exchange deposit paths remain functional before committing larger sums.

Social Engineering — Not a Code Flaw — Enabled the Theft

Investigators subsequently determined that the exploit was carried out through a prolonged social engineering campaign rather than a vulnerability in Drift's code. The attack method reflects a broader trend documented by security firms in which threat actors — particularly those linked to North Korea — target individual developers and employees rather than protocol code, exploiting human trust where technical defenses hold firm.

According to a Chainalysis report, the attackers spent approximately six months impersonating representatives of a quantitative trading firm. During that period, they attended industry events, met with Drift contributors, and deposited over $1 million into the protocol to establish credibility before compromising developers' devices.

The attackers then leveraged Solana's durable nonce feature to obtain pre-signed approvals from two of Drift's five Security Council members. They additionally created a low-value token called CarbonVote Token (CVT), artificially inflated its price through wash trading, and used it as collateral to raise borrowing limits. The protocol was subsequently drained through 31 withdrawals executed over roughly 12 minutes, according to Chainalysis.

Analysts Continue Tracking Stolen Assets

The impact of the breach extended well beyond Drift itself. Chainalysis reports that at least 20 Solana-based projects experienced disruptions because they relied on Drift's vault structure as a yield source. The incident also contributed to a broader decline in activity across Solana decentralized finance projects, highlighting the systemic risk created when multiple protocols depend on a single platform's infrastructure.

Despite the latest laundering effort, blockchain analysts continue to monitor the stolen assets. Organizations including Chainalysis, Elliptic, and Merkle Science track illicit transactions using wallet clustering, time-gap analysis, and cross-chain tracing techniques. While recovering funds becomes significantly more difficult after they pass through a mixer, there have been instances where stolen cryptocurrency was either returned or frozen through the efforts of blockchain analysts.

The most recent Tornado Cash deposits indicate that the Drift exploiter has resumed active laundering of the stolen funds. With approximately $240 million of the original $285 million still unaccounted for relative to the amounts moved in this latest batch, analysts are likely to watch for additional transfers in the coming days.