The $270 million Drift exploit has sent shockwaves through the crypto community, not because of the scale of the loss, but due to the sophisticated nature of the attack. According to Drift, the assault was a six-month campaign involving fake identities, in-person meetings across multiple countries, and carefully cultivated trust. The attackers, allegedly from North Korea, didn't just exploit a system vulnerability; they became an integral part of it.
This new threat is forcing a broader reckoning across decentralized finance, with many security leaders acknowledging that the real vulnerabilities may lie outside the codebase. Alexander Urbelis, CISO at ENS Labs, argues that the framing of these incidents as 'hacks' is outdated and that they should be referred to as 'intelligence operations.' The people who attended conferences, met Drift contributors in person, and deposited a million dollars to build credibility are not opportunistic hackers but patient operators who embed themselves socially before making a move on-chain.
This characterization suggests that Drift represents a new playbook where attackers behave less like hackers and more like operators who infiltrate socially before executing an attack. The tactics themselves are not entirely new, as investigations have shown North Korean operatives infiltrating crypto firms by posing as developers and securing roles under fake identities.
However, the Drift incident suggests that these efforts have escalated, from gaining access through hiring pipelines to running months-long, in-person relationship-building operations before executing an attack. The shift is what has many security leaders most concerned, as even the most rigorously audited protocol can still fail if a contributor is compromised.
David Schwed, COO of SVRN and former CISO at Robinhood and Galaxy, sees the Drift case as a wake-up call, arguing that protocols need to understand what they're up against – well-planned, months-long operations with dedicated resources, fabricated identities, and a deliberate human element. The human element is the Achilles' heel for many organizations, as many DeFi teams remain small, fast-moving, and built on trust.
When a handful of individuals control critical access, compromising one can be enough. Schwed argues that the response needs to be updated, with a well-fortified security program that protects not just the technology but also the people and the process.
Security needs to be foundational to the project and the team. Some protocols are already adjusting, with Jupiter expanding its use of multisigs and timelocks while investing in detection systems and internal training. The surface area for attacks has broadened substantially, now including governance, contributors, and operational security. Even then, complacency remains the biggest risk, and there is no end-state for security.
For protocols like dYdX, the Drift incident reinforces a reality that can't be engineered away entirely – crypto projects are being increasingly targeted by state-sponsored bad actors. Developers must take precautions to prevent and mitigate the impact of social engineering compromises, but users should also be aware that given the increasing sophistication of bad actors, the risk of such compromises cannot be totally eliminated. The evolving threat model is also shifting responsibility toward users themselves, who should take the time to understand the technical architecture of protocols or smart contracts that hold their funds and factor into their risk assessments the role and nature of any multisigs for software upgrades.
The Drift exploit underscores a more uncomfortable conclusion: that trust itself has become a vulnerability. The Drift exploit wasn't a code vulnerability; it was a six-month intelligence operation that exploited trust between humans. In practice, that means designing systems that assume compromise – not just bugs. Smart contract audits are table stakes; the real attack surface is your team, your multisig signers, and every device they touch.
That mindset is becoming central to how DeFi approaches security, starting with a threat model that asks not just how a protocol works but how it could fail. The Drift exploit may be remembered less for the funds lost than for what it revealed – that the biggest risks in DeFi may no longer live in the code but in the people who run it.