• bitcoinBitcoin (BTC) $ 70,837.00
  • ethereumEthereum (ETH) $ 2,177.89
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 599.37
  • xrpXRP (XRP) $ 1.33
  • usd-coinUSDC (USDC) $ 1.00
  • solanaSolana (SOL) $ 81.88
  • tronTRON (TRX) $ 0.316977
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.091372
  • usdsUSDS (USDS) $ 0.999896
  • whitebitWhiteBIT Coin (WBT) $ 52.57
  • leo-tokenLEO Token (LEO) $ 10.14
  • hyperliquidHyperliquid (HYPE) $ 38.57
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.248639
  • bitcoin-cashBitcoin Cash (BCH) $ 440.13
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 8.76
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 325.46
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.999461
  • canton-networkCanton (CC) $ 0.147048
  • zcashZcash (ZEC) $ 317.33
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.155725
  • memecoreMemeCore (M) $ 2.67
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.998833
  • usd1-wlfiUSD1 (USD1) $ 0.999253
  • litecoinLitecoin (LTC) $ 53.97
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999944
  • avalanche-2Avalanche (AVAX) $ 9.04
  • hedera-hashgraphHedera (HBAR) $ 0.089407
  • wethWETH (WETH) $ 2,268.37
  • rainRain (RAIN) $ 0.007957
  • suiSui (SUI) $ 0.908620
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • usdt0USDT0 (USDT0) $ 0.998824
  • bittensorBittensor (TAO) $ 322.34
  • the-open-networkToncoin (TON) $ 1.22
  • crypto-com-chainCronos (CRO) $ 0.069712
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.091987
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,695.82
  • pax-goldPAX Gold (PAXG) $ 4,704.92
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.655771
  • polkadotPolkadot (DOT) $ 1.25
  • global-dollarGlobal Dollar (USDG) $ 0.999872
  • uniswapUniswap (UNI) $ 3.05
  • skySky (SKY) $ 0.076267
  • okbOKB (OKB) $ 83.18
  • falcon-financeFalcon USD (USDF) $ 0.997847
  • nearNEAR Protocol (NEAR) $ 1.33
  • pi-networkPi Network (PI) $ 0.167849
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.663860
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • usddUSDD (USDD) $ 0.999873
  • pepePepe (PEPE) $ 0.000003
  • ripple-usdRipple USD (RLUSD) $ 0.999987
  • aaveAave (AAVE) $ 89.58
  • internet-computerInternet Computer (ICP) $ 2.44
  • bitget-tokenBitget Token (BGB) $ 1.89
  • bfusdBFUSD (BFUSD) $ 0.999501
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ethereum-classicEthereum Classic (ETC) $ 8.39
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ondo-financeOndo (ONDO) $ 0.250484
  • gatechain-tokenGate (GT) $ 6.48
  • kucoin-sharesKuCoin (KCS) $ 8.31
  • quant-networkQuant (QNT) $ 72.89
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • render-tokenRender (RENDER) $ 2.01
  • pump-funPump.fun (PUMP) $ 0.001746
  • algorandAlgorand (ALGO) $ 0.109608
  • morphoMorpho (MORPHO) $ 1.71
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.086640
  • cosmosCosmos Hub (ATOM) $ 1.79
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • nexoNEXO (NEXO) $ 0.870126
  • kaspaKaspa (KAS) $ 0.031839
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • usdtbUSDtb (USDTB) $ 1.00
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.05
  • worldcoin-wldWorldcoin (WLD) $ 0.255115
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.086806
  • blockchain-capitalBlockchain Capital (BCAP) $ 83.06
  • wbnbWrapped BNB (WBNB) $ 759.61
  • official-trumpOfficial Trump (TRUMP) $ 2.91
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • midnight-3Midnight (NIGHT) $ 0.040810
  • filecoinFilecoin (FIL) $ 0.878243
  • ousgOUSG (OUSG) $ 114.85
  • aptosAptos (APT) $ 0.823103
  • flare-networksFlare (FLR) $ 0.007377
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • beldexBeldex (BDX) $ 0.079843
  • arbitrumArbitrum (ARB) $ 0.101790
  • yldsYLDS (YLDS) $ 0.999910
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.007154
  • hash-2Provenance Blockchain (HASH) $ 0.010812
  • xdce-crowd-saleXDC Network (XDC) $ 0.030295
  • ghoGHO (GHO) $ 0.999490
  • justJUST (JST) $ 0.065622
  • jupiter-exchange-solanaJupiter (JUP) $ 0.159228
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.996125
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • stable-2​​Stable (STABLE) $ 0.025498
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.233486
  • bonkBonk (BONK) $ 0.000006
  • true-usdTrueUSD (TUSD) $ 0.999473
  • clbtcclBTC (CLBTC) $ 76,920.00
  • layerzeroLayerZero (ZRO) $ 1.94
  • a7a5A7A5 (A7A5) $ 0.012328
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.47
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.649263
  • euro-coinEURC (EURC) $ 1.17
  • siren-2Siren (SIREN) $ 0.563732
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • blockstackStacks (STX) $ 0.221182
  • dashDash (DASH) $ 32.01
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006336
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999606
  • chilizChiliz (CHZ) $ 0.038271
  • dexeDeXe (DEXE) $ 8.09
  • tezosTezos (XTZ) $ 0.351279
  • sei-networkSei (SEI) $ 0.054946
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • usxUSX (USX) $ 0.999560
  • kinesis-goldKinesis Gold (KAU) $ 151.38
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • decredDecred (DCR) $ 20.64
  • hastra-primePRIME (PRIME) $ 1.03
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • adi-tokenADI (ADI) $ 4.48
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • ether-fiEther.fi (ETHFI) $ 0.439820
  • cocaCOCA (COCA) $ 1.30
  • edgexedgeX (EDGE) $ 0.985769
  • sun-tokenSun Token (SUN) $ 0.017421
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • bitcoin-svBitcoin SV (BSV) $ 16.15
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • gnosisGnosis (GNO) $ 122.83
  • apenftAINFT (NFT) $ 0.00000033
  • monadMonad (MON) $ 0.029841
  • curve-dao-tokenCurve DAO (CRV) $ 0.213308
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • aerodrome-financeAerodrome Finance (AERO) $ 0.336939
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • venice-tokenVenice Token (VVV) $ 6.81
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • injective-protocolInjective (INJ) $ 2.90
  • plasmaPlasma (XPL) $ 0.118944
  • doublezeroDoubleZero (2Z) $ 0.081221
  • kinesis-silverKinesis Silver (KAG) $ 73.21
  • kaiaKaia (KAIA) $ 0.047070
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • spx6900SPX6900 (SPX) $ 0.295670
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • fraxLegacy Frax Dollar (FRAX) $ 0.993491
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • syrupMaple Finance (SYRUP) $ 0.235867
  • usdaiUSDai (USDAI) $ 1.00
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • official-foOfficial FO (FO) $ 0.268490
  • lido-daoLido DAO (LDO) $ 0.315204
  • celestiaCelestia (TIA) $ 0.294278
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • flokiFLOKI (FLOKI) $ 0.000027
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • the-graphThe Graph (GRT) $ 0.024159
  • jasmycoinJasmyCoin (JASMY) $ 0.005251
  • conflux-tokenConflux (CFX) $ 0.049630
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • crvusdcrvUSD (CRVUSD) $ 0.999817

How North Korea’s 6-month long secret espionage program has crypto community rethinking security

0 0


When Drift disclosed the details behind its $270 million exploit, the most unsettling part wasn’t the scale of the loss — it was how it happened.

According to the team behind the protocol, the attack wasn’t a smart contract bug or a clever piece of code manipulation. It was a six-month campaign involving fake identities, in-person meetings across multiple countries and carefully cultivated trust. The attackers, allegedly from North Korea, didn’t just find a vulnerability in the system. They became part of it.

This new threat is now forcing a broader reckoning across decentralized finance.

For years, the industry has treated security as a technical problem, something that could be solved with audits, formal verification and better code. But the Drift incident suggests something far more complex: that the real vulnerabilities may lie outside the codebase altogether.

Alexander Urbelis, chief information security officer (CISO) at ENS Labs, argues the framing itself is already outdated.

“We need to stop calling these ‘hacks’ and start calling them what they are: intelligence operations,” Urbelis told CoinDesk. “The people who showed up at conferences, who met Drift contributors in person across multiple countries, who deposited a million dollars of their own money to build credibility: that’s tradecraft. It’s the kind of thing you’d expect from a case officer, not a hacker.”

If that characterization holds, then Drift represents a new playbook: one where attackers behave less like opportunistic hackers and more like patient operators embedding themselves socially before making a move onchain.

“North Korea isn’t scanning for vulnerable contracts anymore. They’re scanning for vulnerable people… That’s not hacking. That’s running agents,” Urbelis added.

The tactics themselves aren’t entirely new.

Investigations in recent years have shown North Korean operatives infiltrating crypto firms by posing as developers, passing job interviews and even securing roles under fake identities. But the Drift incident suggests those efforts have escalated — from gaining access through hiring pipelines to running months-long, in-person relationship-building operations before executing an attack.

‘The Achilles’ heel’

That shift is what has many security leaders most concerned. Even the most rigorously audited protocol can still fail if a contributor is compromised.

David Schwed, chief operating officer of SVRN and a former CISO at both Robinhood and Galaxy, sees the Drift case as a wake-up call.

“Protocols need to understand what they’re up against. These aren’t simple exploits. These are well-planned, months-long operations with dedicated resources, fabricated identities, and a deliberate human element,” Schwed told CoinDesk. “That human element is the Achilles’ heel for many organizations.”

Many DeFi teams remain small, fast-moving and built on trust. But when a handful of individuals control critical access, compromising one can be enough.

Schwed argues that the response needs to be updated. “The answer is a well-fortified security program that protects not just the technology, but the people and the process… Security needs to be foundational to the project and the team.”

Some protocols are already adjusting. At Jupiter, one of Solana’s largest DeFi platforms, the baseline of audits and formal verification remains, but leaders claim it’s no longer sufficient.

“Clearly, securing code via multiple independent audits, open sourcing, and formal verification is just table stakes. The surface area for attacks has broadened substantially,” said COO Kash Dhanda.

That broader surface now includes governance, contributors and operational security. Jupiter has expanded its use of multisigs and timelocks while investing in detection systems and internal training.

“Given that flesh is more vulnerable than code, we’re also updating opsec training and monitoring for key team members,” Dhanda said.

Even then, he added, “there is no end-state for security” and complacency remains the biggest risk.

For protocols like dYdX, the Drift incident reinforces a reality that can’t be engineered away entirely.

“It’s an unfortunate fact of life that crypto projects are being increasingly targeted by state-sponsored bad actors… developers must take precautions to prevent and mitigate the impact of social engineering compromises, but users should also be aware that given the increasing sophistication of bad actors the risk of such compromises cannot be totally eliminated,” said David Gogel, COO of dYdX Labs.

That evolving threat model is also shifting responsibility toward users themselves.

“Users who are active in DeFi should take the time to understand the technical architecture of protocols or smart contracts that hold their funds, and should factor into their risk assessments the role and nature of any multisigs for software upgrades and the possibility that those could be maliciously compromised,” Gogel added.

‘Threat model’

For some founders, the Drift exploit underscores a more uncomfortable conclusion: that trust itself has become a vulnerability.

“The Drift exploit wasn’t a code vulnerability. It was a six-month intelligence operation that exploited trust between humans,” said Lucas Bruder, CEO of Jito Labs.

In practice, that means designing systems that assume compromise — not just bugs.

“Smart contract audits are table stakes. The real attack surface is your team, your multisig signers, and every device they touch.”

That mindset is becoming central to how DeFi approaches security. Schwed of SVRN says it starts with asking not just how a protocol works, but how it could fail.

“Start with a threat model. Ask yourself, how can I be exploited? If one of the project owners becomes compromised, what’s the blast radius of that scenario?”

In that sense, the Drift exploit may be remembered less for the funds lost than for what it revealed — that the biggest risks in DeFi may no longer live in the code, but in the people who run it.

Read more: How North Korea Infiltrated the Crypto Industry



Source link

Leave A Reply

Your email address will not be published.