The recent $270 million exploit of Drift has sent shockwaves through the crypto community, not because of the scale of the loss, but due to the sophisticated nature of the attack. Unlike typical smart contract bugs or code manipulation, this incident involved a six-month campaign of fake identities, in-person meetings, and carefully built trust.
The attackers, allegedly from North Korea, effectively became part of the system, exposing a vulnerability that lies outside the codebase. This new threat is prompting a broader reassessment of security across decentralized finance. For years, the industry has treated security as a technical problem, solvable through audits, formal verification, and better code. However, the Drift incident suggests a more complex issue, where real vulnerabilities may lie outside the codebase.
According to Alexander Urbelis, chief information security officer at ENS Labs, the framing of these attacks as 'hacks' is outdated. Instead, they should be recognized as 'intelligence operations,' given the level of tradecraft involved, similar to what one would expect from a case officer rather than a hacker. If this characterization holds, then the Drift incident represents a new playbook, where attackers behave more like patient operators who embed themselves socially before making a move on-chain. Urbelis notes that North Korea is no longer just scanning for vulnerable contracts but is now scanning for vulnerable people, a tactic that is more aligned with running agents than hacking.
While the tactics themselves are not entirely new, investigations have shown that North Korean operatives have been infiltrating crypto firms by posing as developers, securing roles under fake identities, and even passing job interviews. The Drift incident suggests that these efforts have escalated, from gaining access through hiring pipelines to running months-long, in-person relationship-building operations before executing an attack.
This shift is what concerns many security leaders the most, as even the most rigorously audited protocol can still fail if a contributor is compromised. David Schwed, chief operating officer of SVRN and former CISO at both Robinhood and Galaxy, views the Drift case as a wake-up call. Protocols need to understand that they are up against well-planned, months-long operations with dedicated resources, fabricated identities, and a deliberate human element. This human element is the Achilles' heel for many organizations.
Many DeFi teams remain small, fast-moving, and built on trust, but when a handful of individuals control critical access, compromising one can be enough. Schwed argues that the response needs to be updated, with a well-fortified security program that protects not just the technology but also the people and the process. Security needs to be foundational to the project and the team.
Some protocols are already adjusting their strategies. At Jupiter, one of Solana's largest DeFi platforms, while audits and formal verification remain crucial, leaders recognize that these measures are no longer sufficient on their own. The surface area for attacks has broadened substantially, now including governance, contributors, and operational security.
Jupiter has expanded its use of multisigs and timelocks, invested in detection systems, and provided internal training. However, even with these measures, complacency remains the biggest risk. For protocols like dYdX, the Drift incident reinforces the reality that some risks cannot be entirely engineered away.
Crypto projects are being increasingly targeted by state-sponsored bad actors, and while developers must take precautions to prevent and mitigate the impact of social engineering compromises, users should also be aware that the risk of such compromises cannot be totally eliminated. The evolving threat model is shifting responsibility toward users themselves, who should take the time to understand the technical architecture of protocols or smart contracts that hold their funds and factor into their risk assessments the role and nature of any multisigs for software upgrades and the possibility that those could be maliciously compromised.
For some founders, the Drift exploit underscores a more uncomfortable conclusion: that trust itself has become a vulnerability. The Drift exploit was not a code vulnerability but a six-month intelligence operation that exploited trust between humans. In practice, this means designing systems that assume compromise, not just bugs.
Smart contract audits are essential, but the real attack surface includes the team, multisig signers, and every device they touch. This mindset is becoming central to how DeFi approaches security, starting with a threat model that asks not just how a protocol works but how it could fail.
The Drift exploit may be remembered less for the funds lost than for what it revealed: that the biggest risks in DeFi may no longer live in the code but in the people who run it.