ME News reports that on April 5 (UTC+8), Drift Protocol posted on X that preliminary investigations into the April 1, 2026, attack indicate the operation was orchestrated by UNC4736, a North Korean state-sponsored hacking group also known as AppleJeus or Citrine Sleet. Since autumn 2025, the group engaged in six months of in-person interactions with Drift contributors by sending intermediaries to crypto conferences and establishing fake quantitative trading firms, tricking them into downloading malicious code libraries or applications. Drift has since frozen all protocol functions and moved compromised wallets out of multisignature control. Mandiant has been invited to conduct an in-depth forensic investigation. The investigation confirmed that on-chain funds used to test the operation can be traced back to the attackers of the Radiant Capital breach in October 2024. (Source: ChainCatcher)
Drift Protocol hack linked to North Korean hackers UNC4736
KuCoinFlashShare






Drift Protocol revealed on X that the April 1, 2026, exploit was carried out by UNC4736, a North Korea-linked group also known as AppleJeus. The hackers spent six months building trust with Drift contributors through conferences and fake firms before deploying malicious code. All protocol functions are now frozen, and compromised wallets have been removed from multisignature. Mandiant is assisting with a deeper investigation. The attack’s test phase funds trace back to the October 2024 Radiant Capital breach. Traders are closely monitoring altcoins amid rising volatility in the Fear & Greed Index.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.