The revelation of a $270 million exploit by Drift has sent shockwaves through the crypto community, not because of the scale of the loss, but due to the nature of the attack. The incident involved a six-month campaign of fake identities, in-person meetings, and carefully cultivated trust, with the attackers, allegedly from North Korea, becoming an integral part of the system. This new threat is prompting a broader reevaluation of security across decentralized finance. For years, the industry has focused on solving security issues through audits, formal verification, and better code.
However, the Drift incident suggests that real vulnerabilities may lie outside the codebase altogether. According to Alexander Urbelis, chief information security officer at ENS Labs, the framing of these incidents as 'hacks' is outdated, and they should be referred to as 'intelligence operations.' The people who attended conferences, met Drift contributors in person, and deposited a million dollars to build credibility were using tradecraft, similar to that of a case officer, rather than a hacker. If this characterization holds, then Drift represents a new playbook, where attackers behave less like opportunistic hackers and more like patient operators who embed themselves socially before making a move on the blockchain. The tactics themselves are not entirely new, as investigations have shown North Korean operatives infiltrating crypto firms by posing as developers and securing roles under fake identities.
However, the Drift incident suggests that these efforts have escalated, from gaining access through hiring pipelines to running months-long, in-person relationship-building operations before executing an attack. This shift is what concerns many security leaders, as even the most rigorously audited protocol can still fail if a contributor is compromised.
David Schwed, chief operating officer of SVRN, sees the Drift case as a wake-up call, stating that protocols need to understand what they are up against, as these are not simple exploits, but well-planned, months-long operations with dedicated resources, fabricated identities, and a deliberate human element. The human element is the Achilles' heel for many organizations, as many DeFi teams remain small, fast-moving, and built on trust. When a handful of individuals control critical access, compromising one can be enough.
Schwed argues that the response needs to be updated, with a well-fortified security program that protects not just the technology, but the people and the process, and security needs to be foundational to the project and the team. Some protocols are already adjusting, with Jupiter, one of Solana's largest DeFi platforms, expanding its use of multisigs and timelocks, investing in detection systems and internal training, and updating opsec training and monitoring for key team members. However, even then, there is no end-state for security, and complacency remains the biggest risk.
For protocols like dYdX, the Drift incident reinforces a reality that cannot be engineered away entirely, and developers must take precautions to prevent and mitigate the impact of social engineering compromises. The evolving threat model is also shifting responsibility toward users themselves, with users who are active in DeFi needing to take the time to understand the technical architecture of protocols or smart contracts that hold their funds and factor into their risk assessments the role and nature of any multisigs for software upgrades.
The Drift exploit underscores a more uncomfortable conclusion: that trust itself has become a vulnerability, and designing systems that assume compromise, not just bugs, is essential. This mindset is becoming central to how DeFi approaches security, with a focus on asking not just how a protocol works, but how it could fail, and starting with a threat model to identify potential vulnerabilities.