the tl;dr of the drift protocol shenanigans
> be drift protocol
> decentralized trading thingy
> built on solana or something
> april 1st
> april fools
> jk $280,000,000 (approx.) stolen
> rewind
> fall, 2025
> drift people at conference
> crypto nerds approach them
> crypto nerds say theyre at some fancy place
> want to integrate with drift
> crypto nerds sneeky
> crypto nerds only talk to specific people
> wtf how they know who is who?
> crypto nerds hang out in person
> meet at multiple conferences
> crypto nerds smart af, know crypto fr
> these_guys_are_chill.jpeg
> december, january comes around
> setup private group chat
> long meetings about strategy and stuff
> contracts and on-boarding stuff
> fancy_meetings.mp4
> crypto nerds put up $1m in cash for investment
> these_guys_are_legit.mp3
> hang out more in person
> start collaborating with coding projects
> april 1st
> $280,000,000 missing
> cool bros missing
> wtf?
> all chat logs gone
> all software sharing stuff gone
> wtf?
> 1-800-help-us-mandiant
> digital forensic and incident response time
> mandiant looks inside
> 1 drift person compromised from code sharing stuff
> 2nd drift person compromised from some test thingy
> wtf who is this
> look inside
> UNC4736
> unironically north korean spies
> sent abroad to do in-person social engineering
> crypto forensic nerds tie it to radiant capitol hack
> mandiant still investigating right now
tl;dr north korean nerds leave north korea, act like total bros, hang out at conferences, have tons of money, bamboozle people in long-term social engineering and espionage stuff to steal hundreds of millions of dollars