- Drift Protocol lost approximately half of its TVL to hackers on April 1, 2026.
- Mandiant identified North Korean threat group UNC6862 as being behind the hack.
- Drift Foundation has frozen approximately $9.2 million of the stolen funds in transit.
Drift Foundation has released an update on the April 1, 2026, Drift Protocol hack, describing the state of affairs and efforts to recover approximately $295 million taken from users. According to the group, efforts are ongoing to track, trace, and recover stolen funds. The foundation assured users that recovered funds will be directed to the DFX recovery pool, regardless of the recovery route, through a freeze, a bounty, or law enforcement.
The April 1 incident wiped out 50% of Drift Protocol’s Total Value Locked (TVL). Shortly after the exploit, security firms, including TRM Labs and Mandiant, attributed the hack to UNC4736, a state-affiliated North Korean (DPRK) cybercriminal group.
How Drift is Working to Recover Funds
In their latest update, Drift Foundation noted that they brought in Mandiant, zeroShadow, and SEAL 911 to investigate and trace the stolen funds. Meanwhile, Mandiant has identified the attacker as UNC6862, a North Korean threat group. zeroShadow, on its part, has tracked the stolen funds, including the laundering that began in July. According to the Foundation, zeroShadow has already shared its findings with law enforcement.
Latest findings reveal that approximately 130,259 ETH of the stolen funds were bridged on Ethereum across four wallets, three of which hold 107,165 ETH that have not been moved. Meanwhile, the remaining wallet sent about 23,094 ETH into Tornado Cash on July 23.
An Assurance for Users
Drift Foundation assured users that it is working with zeroShadow and law enforcement to track and flag withdrawals linked to the stolen funds. However, the group noted that some of the funds have been transferred across multiple blockchains and jurisdictions, making it complicated to return frozen funds.
Meanwhile, the group has frozen about $9.2 million that the attacker moved through Tornado Cash in August. According to Drift Foundation, the process involves law enforcement and takes time.
Experts who analyzed the April 1 attack described it as unique, stating that it relied on a highly coordinated, long-term hybrid strategy of deep corporate espionage and on-chain manipulation rather than a standard smart contract code bug.
Related: Drift Protocol Plans $147.5M Recovery After Major Exploit Hit
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.