Driftl: The April 1 attack was a long-term infiltration operation planned by a North Korean hacker group
Comparing news, Drift Protocol posted an article on the X platform stating that preliminary investigations into the April 1, 2026 attack showed that the operation was planned by UNC4736 (also known as AppleJeus or Citrine Sleet), a hacker group supported by the North Korean government. Since fall 2025, the organization has been interacting face-to-face with Drift contributors for six months and inducing them to download malicious codebases or apps by sending intermediaries to crypto conferences and setting up fake quantitative trading companies. Currently, Drift has frozen all protocol features and removed the damaged wallet from multi-signature. Mandiant has been invited to participate in an in-depth forensic investigation. The investigation confirmed that the on-chain money used to test the operation went to Radiant Capital attackers dating back to October 2024.




