Campaigns
285 Million Drift Hack Traced To Six

285 Million Drift Hack Traced To Six

Admin Key ExploitFake OracleFake CollateralActive Laundering
The Drift Protocol Exploit involved a sophisticated attack on the Drift Protocol, resulting in the theft of over $285 million in just 10 seconds. The attacker utilized a combination of admin key exploits, fake oracles, and fake collateral to drain the protocol's vaults. The funds were then scattered across 63,000+ wallets using automated bots, making recovery efforts extremely challenging.

Indicators of Compromise

No domains found for this campaign

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION


🔍  Detection Strategies  ·  attack.mitre.org/detectionstrategies

DET0146

Detection of Data Destruction Across Platforms

Monitor for mass file overwrite and deletion operations across platforms. Flag bulk DeleteObject/DeleteBucket API calls, mass resource deletion in Azure activity logs, VSS deletion, MBR modifications, and large-scale SMB share removals. Correlate with process behavior and endpoint telemetry.

↳ Drift: 31 rapid vault withdrawals executed within ~12 minutes on April 1

DET0249

Behavior-chain detection for T1610 Deploy Container

Detect remote or API-driven container creation with non-allow-listed images or risky runtime attributes (--privileged, host PID/NET namespaces, sensitive mounts). Correlates create → start → first network/process actions within a short time window.

↳ Drift: automated bot infrastructure for 63,000+ wallet fund dispersion

DET0309

Compromised software/update chain

Detect tampered application or update delivery: installer writes/replaces binaries; on first run spawns scripts or unsigned DLLs and beacons to non-approved hosts. Correlates installer process → file metadata changes → first-run child anomalies → unexpected outbound connections.

↳ Drift: malicious code repo shared by UNC4736 for vault frontend deployment

Observed Countries250

AD (557)
AE (8)
AF (866)
AG (197)
AI (886)
AL (224)
AM (228)
AO (352)
AQ (654)
AR (758)
AS (690)
AT (787)
AU (716)
AW (424)
AX (963)
AZ (401)
BA (268)
BB (51)
BD (791)
BE (200)
BF (877)
BG (173)
BH (45)
BI (644)
BJ (328)
BL (573)
BM (582)
BN (555)
BO (171)
BQ (36)
BR (731)
BS (800)
BT (59)
BV (779)
BW (50)
BY (816)
BZ (584)
CA (594)
CC (642)
CD (233)
CF (894)
CG (71)
CH (876)
CI (105)
CK (410)
CL (709)
CM (510)
CN (847)
CO (581)
CR (520)
CU (620)
CV (234)
CW (863)
CX (762)
CY (451)
CZ (282)
DE (460)
DJ (178)
DK (775)
DM (292)
DO (557)
DZ (768)
EC (638)
EE (246)
EG (727)
EH (871)
ER (785)
ES (676)
ET (876)
FI (150)
FJ (459)
FK (364)
FM (536)
FO (490)
FR (282)
GA (720)
GB (219)
GD (538)
GE (859)
GF (604)
GG (125)
GH (485)
GI (654)
GL (557)
GM (492)
GN (970)
GP (688)
GQ (419)
GR (614)
GS (100)
GT (944)
GU (542)
GW (213)
GY (337)
HK (718)
HM (409)
HN (778)
HR (489)
HT (321)
HU (580)
ID (349)
IE (713)
IL (944)
IM (850)
IN (557)
IO (953)
IQ (133)
IR (611)
IS (32)
IT (952)
JE (154)
JM (396)
JO (212)
JP (395)
KE (134)
KG (296)
KH (949)
KI (108)
KM (103)
KN (962)
KP (25)
KR (151)
KW (589)
KY (210)
KZ (958)
LA (818)
LB (102)
LC (229)
LI (814)
LK (774)
LR (810)
LS (486)
LT (884)
LU (227)
LV (283)
LY (341)
MA (467)
MC (68)
MD (563)
ME (341)
MF (17)
MG (202)
MH (886)
MK (828)
ML (721)
MM (756)
MN (929)
MO (526)
MP (718)
MQ (438)
MR (645)
MS (979)
MT (719)
MU (913)
MV (32)
MW (447)
MX (117)
MY (208)
MZ (61)
NA (68)
NC (92)
NE (541)
NF (272)
NG (432)
NI (25)
NL (147)
NO (748)
NP (722)
NR (306)
NU (390)
NZ (364)
OM (370)
PA (327)
PE (205)
PF (838)
PG (918)
PH (927)
PK (715)
PL (751)
PM (322)
PN (721)
PR (636)
PS (478)
PT (571)
PW (382)
PY (72)
QA (381)
RE (684)
RO (360)
RS (10)
RU (616)
RW (148)
SA (358)
SB (242)
SC (841)
SD (957)
SE (920)
SG (571)
SH (584)
SI (5)
SJ (67)
SK (418)
SL (350)
SM (785)
SN (694)
SO (472)
SR (234)
SS (968)
ST (150)
SV (498)
SX (873)
SY (92)
SZ (622)
TC (635)
TD (128)
TF (29)
TG (679)
TH (733)
TJ (836)
TK (840)
TL (257)
TM (743)
TN (701)
TO (400)
TR (549)
TT (727)
TV (928)
TW (967)
TZ (761)
UA (190)
UG (553)
UM (809)
US (419)
UY (195)
UZ (221)
VA (582)
VC (130)
VE (857)
VG (807)
VI (732)
VN (611)
VU (31)
WF (637)
WS (365)
XK (914)
YE (877)
YT (372)
ZA (652)
ZM (298)
ZW (327)