
North Korean operatives conducted a six-month infiltration campaign targeting Drift protocol, resulting in a $270 million exploit. Rather than exploiting code vulnerabilities, attackers built trust through fake identities, in-person meetings across multiple countries, and deposited funds to establish credibility. Security experts now characterize this as an intelligence operation, not a traditional hack. The incident has prompted DeFi protocols to expand security beyond code audits to include operational security, governance, and personnel vetting.