North Korean hackers drain Drift $285M; Stabble urges liquidity withdrawals
North Korea-linked operators hit Solana DeFi twice in eight days. Drift lost $285M. Stabble told users to pull liquidity after its ex-CTO was flagged as a suspected DPRK hacker.
DPRK footprint widens on Solana
- Stabble urged immediate withdrawals after its former CTO, “Keisuke Watanabe,” was identified as an alleged North Korean operative. The team confirmed it had an NK developer until a year ago in a public update and issued an “EMERGENCY” alert on X here.
- Stabble’s TVL fell 62% intraday, from about $1.75M to under $663K, per DeFiLlama data.
Drift hack: largest DeFi exploit of 2026 so far
- Drift Protocol lost $285M on April 1. TRM Labs, Elliptic, and Chainalysis attributed the attack to DPRK here.
- The theft was executed in roughly 10 seconds via social engineering, oracle manipulation, and pre-signed durable nonce transactions; funds were swapped into USDC and SOL, then bridged to Ethereum via CCTP (SecurityWeek).
Market read
- SOL hovered near $80 on the chart during the turbulence (TradingView).
- One trader flagged a bearish-flag pattern and a potential path to $45 in a breakdown scenario (tweet).
Security posture and tail risk
- The Solana Foundation says ecosystem security programs are active, aiming to contain contagion (program update).
- DPRK-linked groups reportedly stole $2B in crypto in 2025, accounting for roughly 60% of global crypto hacks that year (DLNews).







