Drift crypto platform confirms $280 million stolen in hack as researchers point finger at North Korea
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述。首先,我需要仔细阅读这篇文章,了解主要事件和关键点。 文章讲的是去中心化金融平台Drift发生了安全事件,导致2.8亿美元被提取。事件发生在周三,Drift在当晚发布了事后分析报告。攻击者通过一种“新颖的攻击”方式,迅速接管了公司安全理事会的行政权限。报告中提到这是一次高度复杂的操作,准备时间长达数周,并分阶段执行。 攻击影响了平台的所有存款功能,包括借贷、质押和交易资金。Drift否认程序或智能合约有漏洞,认为事件是由于未经授权或被误导的交易批准所导致,很可能是通过复杂的社交工程实现的。攻击者在3月23日设置攻击,并于4月1日执行了两个预先签名的交易。Drift指出,这次攻击利用了预先签名交易允许延迟执行以及审批流程被破坏的漏洞。 黑客利用控制权移除了预先设定的提款限制。目前Drift正在与多家安全公司合作调查原因,并与桥梁、交易所和执法部门合作追踪和冻结被盗资产。他们还承诺在未来几天发布更全面的事后报告。 此外,区块链安全公司Elliptic指出这次攻击是由朝鲜黑客实施的。朝鲜政府被认为是加密货币盗窃的最大幕后黑手,在去年类似的攻击中窃取了超过20亿美元。美国指控平壤政府利用被盗加密货币资助军事武器计划。Elliptic指出多个迹象表明这次对Drift协议的攻击与朝鲜有关联,并提到这是今年追踪到的第十八起朝鲜相关事件。 其他研究人员也独立指认是朝鲜黑客所为,称使用的战术与去年夏天针对迪拜加密货币公司Bybit的15亿美元黑客攻击相似。最近朝鲜黑客还涉及另一起严重的网络安全事件,涉及广泛使用的Axios库。 总结一下,文章主要讲述了Drift平台遭受2.8亿美元损失的安全事件经过、原因分析以及初步调查结果,并指出此次攻击可能由朝鲜黑客实施。 </think> 去中心化金融平台Drift遭遇安全事件,损失2.8亿美元。黑客通过复杂手段接管系统,利用预签名交易和审批漏洞作案,影响借贷、质押及交易资金。Drift否认技术漏洞,称系社交工程所致,正调查并追讨资产。专家指认朝鲜黑客参与,今年已追踪多起类似事件,损失超3亿美元。 2026-4-2 17:45:43 Author: therecord.media(查看原文) 阅读量:4 收藏

Decentralized finance platform Drift confirmed that $280 million was withdrawn from the platform during a security incident that took place on Wednesday. 

The platform released a post-mortem on Wednesday night explaining that malicious actors gained access to Drift systems through a “novel attack” that involved the “rapid takeover” of the company’s security council administrative powers. 

“This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution,” the statement said. 

The incident affects all money deposited in the platform’s borrow and lend features as well as vault deposits and funds deposited for trading. 

The company denied that there is any bug in Drift’s programs or smart contracts, arguing that the incident was traced back to “unauthorized or misrepresented transaction approvals obtained prior to execution, likely facilitated through… sophisticated social engineering.”

The thieves set up the attack on March 23 and eventually executed two pre-signed transactions on April 1. Drift said the attack was enabled by a combination of the pre-signed transactions that allowed for delayed execution and the compromise of their approvals process. The hacker was able to use their control to remove pre-set withdrawal limits. 

“Drift Protocol is coordinating with multiple security firms to determine the cause of the incident. Drift is also working with bridges, exchanges, and law enforcement to trace and freeze stolen assets,” the company said, urging anyone with more information to come forward.

Drift pledged to release a more comprehensive post-incident report in the coming days. 

On Thursday morning, experts at blockchain security company Elliptic said the attack on Drift was conducted by hackers based in North Korea. The country’s government has been the largest force behind crypto thefts and stole more than $2 billion in similar attacks last year. The U.S. has accused Pyongyang’s government of using the stolen cryptocurrency to fund its military weapons program.

Elliptic said it “identified multiple indicators suggesting that the exploit of Drift Protocol is linked to the Democratic People's Republic of Korea (DPRK).”

“The on-chain behavior, laundering methodologies and network-level indicators associated with the attack are consistent with techniques observed in previous DPRK-attributed operations,” Elliptic explained. “If confirmed, this incident would represent the eighteenth DPRK act Elliptic has tracked this year, with over $300 million stolen so far.”

Several other researchers independently pointed the finger at North Korean hackers as well, saying the tactics used resembled those deployed in the $1.5 billion hack of Dubai-based crypto firm Bybit last summer. 

North Korean hackers were recently implicated in another damaging cybersecurity incident involving the compromise of axios, a wildly popular library used in both front-end apps and back-end systems. On Wednesday night, Microsoft and Crowdstrike confirmed Google’s initial assessment that North Korean hackers were responsible for the attack.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/drift-crypto-confirms-280-million-stolen-north-korea
如有侵权请联系:admin#unsafe.sh