Free NewsletterPro Login

North Korea Hit Crypto From Two Directions This Week. Investors Lost $280 Million in One Attack Alone.

Published Apr 2, 2026
Share:
A safe with crypto coins and a screen showing a downward price graph, set in a server room—a scene highlighting investors' concerns over security breaches linked to North Korea's involvement in the crypto market.
Summary:
  • Hackers linked to North Korea drained $280 million from DeFi platform Drift after spending weeks quietly setting up the attack.
  • The same week, suspected Pyongyang-linked hackers planted malicious code inside Axios - a software tool used by thousands of U.S. companies.
  • North Korea has now stolen more than $300 million in crypto this year alone, according to blockchain security firm Elliptic.

North Korea didn't just rob one crypto platform this week. It hit two targets at the same time - a direct heist and a hidden software trap - in what looks like the most aggressive week of state-backed crypto theft in recent memory.

The Drift Heist

Drift - a decentralized finance platform where investors can lend, borrow, and trade crypto - confirmed Wednesday that attackers pulled $280 million off the platform in a single operation.

This wasn't a code exploit. Drift says its smart contracts and core programs were never breached. Instead, the attackers spent weeks working their way into the company's security council - the group that controls admin-level powers - by tricking insiders into approving access they shouldn't have.

They planted two pre-approved transactions on March 23. Then they waited.

On April 1, they fired both transactions, seized admin controls, stripped out withdrawal caps, and moved $280 million before anyone could stop it. Every dollar in Drift's lending, borrowing, vault, and trading features was exposed.

By Thursday morning, blockchain investigators at Elliptic had tied the attack to North Korea. The transaction patterns and laundering methods matched operations Elliptic has tracked from Pyongyang's hackers before.

If confirmed, it would be the 18th North Korean crypto attack Elliptic has flagged this year.

The Software Trap

The Drift heist wasn't the only move. Days earlier, suspected North Korean hackers broke into the account of a developer who maintains Axios - an open-source tool baked into thousands of company websites across health care, finance, and tech.

For about three hours, the attackers pushed out infected updates to every company that downloaded the software during that window. Security firm Huntress counted around 135 infected machines spread across about a dozen organizations - and that's just the early tally.

Google-owned Mandiant confirmed the North Korea connection. Its chief technology officer said the hackers will likely use whatever access they gained to hunt for crypto stored at those companies.

Full recovery could take months.

What to Watch

North Korea has turned crypto theft into a pillar of its economy. Pyongyang's hackers pulled in more than $2 billion from crypto platforms last year alone, and U.S. officials have said roughly half of the country's missile program is bankrolled by that kind of theft.

This week showed investors two things at once - North Korea can hit a platform head-on and slip into the software supply chain at the same time.

The Drift attack looks a lot like last summer's $1.5 billion Bybit breach. Both relied on tricking people rather than breaking code. Both moved fast once the trap was sprung.

Crypto security isn't just a tech problem anymore - It's a national security one.

Disclosure

Get Market Briefs delivered to your inbox every morning for free!

No fluff. No noise. No politics. Just finance news you can read in 5 minutes.

Blogs

April 29, 2026
What Is Blockchain? A Plain English Guide For Investors
  • Blockchain is a digital ledger that records every transaction on a public network.
  • Once a transaction is recorded, it cannot be changed or deleted.
  • It is the foundation of Bitcoin, Ethereum, and thousands of other cryptocurrencies.
Read More
April 29, 2026
How To Negotiate Bills: The Script That Saves You Hundreds A Year
  • Most monthly bills are negotiable, even though most Americans never try.
  • A simple phone call with the right script can lower your phone, internet, and utility bills.
  • The key rule is to be nice. Customer service reps have more flexibility than most people realize.
Read More
April 29, 2026
75 15 10 Rule: The Budget That Builds Wealth On Autopilot
  • The 75 15 10 rule is a budgeting plan: spend at most 75% of your income, invest at least 15%, and save at least 10%.
  • It works by making sure you pay yourself before you spend.
  • Once your savings target is hit, you shift the 10% over to investing, becoming a 75/25 plan.
Read More
April 29, 2026
How To Rebalance Portfolio: The Strategy That Forces You To Buy Low And Sell High
  • Rebalancing means adjusting your portfolio back to your target allocation when it drifts too far.
  • The two main methods are time-based (rebalance once a year) and threshold-based (rebalance when allocation drifts more than 5%).
  • If you are still adding money, you can rebalance by directing new money instead of selling.
Read More
April 29, 2026
How To Buy Treasury Bonds: A Beginner's Guide
  • Treasury bonds are loans you make to the U.S. government. They are considered the safest investment in the world.
  • You can buy them at TreasuryDirect.gov directly or through any major brokerage.
  • There are three main types: T-Bills, Treasury Notes, and Treasury Bonds. The longer the term, the higher the interest rate.
Read More
April 29, 2026
Forward Vs Futures Contracts: What's The Real Difference?
  • Both forward and futures contracts are deals to buy or sell something at a set price on a future date.
  • Futures trade on exchanges. Forwards are private deals between two parties.
  • Most regular investors do not use either. They are mostly tools for businesses and big institutions.
Read More
April 29, 2026
Alternative Investments Explained: What They Are And Why They Matter
  • Alternative investments are anything that is not a regular stock or bond.
  • The most common types are precious metals, crypto, real estate, commodities, and collectibles.
  • Most investors should hold 5% to 25% of their portfolio in alternatives, depending on risk tolerance.
Read More
April 29, 2026
How To Buy Bitcoin For Beginners: 3 Simple Ways
  • There are three main ways to buy Bitcoin: directly on an exchange, through a Bitcoin ETF, or through a Bitcoin miner stock.
  • Each has its own pros, cons, and tax setup.
  • Most beginners do best starting small and using dollar cost averaging.
Read More
April 29, 2026
How To Follow Smart Money: The 5 Market Shifts Framework
  • "Smart money" means big investors with deep research teams and fast information.
  • You can follow them by watching for 5 types of market shifts.
  • The goal is to spot where money is moving before it shows up on CNBC.
Read More
April 29, 2026
Insider Trading Meaning: What It Really Is (And Why Some Of It Is Legal)
  • Insider trading means buying or selling a stock based on facts the public does not know yet.
  • Some insider trading is legal. Some is a federal crime that can send people to prison.
  • The SEC tracks every legal insider trade in a public file called Form 4.
Read More
1 2 3 19
Share via
Copy link