Drift Protocol says April 1 attack tied to North Korea's UNC4736

Drift Protocol said on X on April 5 (UTC+8) that its preliminary probe into the April 1, 2026, exploit points to UNC4736, a North Korean state-sponsored hacking group also tracked as AppleJeus or Citrine Sleet. According to Drift, the actors spent roughly six months cultivating relationships with contributors starting in autumn 2025. The group allegedly dispatched intermediaries to crypto conferences and set up sham quantitative trading firms, ultimately persuading targets to download malicious code libraries or applications. Drift said it has frozen all protocol functions and removed compromised wallets from multisignature control. The team has brought in Mandiant to run an in-depth forensic investigation. Drift added that the on-chain funds used to test the operation can be traced to the attackers behind the Radiant Capital breach in October 2024. (Source: ChainCatcher)