Drift exploit: North Korea-linked hackers targeted via Ethereum on-chain messages
Drift, a Solana-based DEX, said it wants to negotiate with hackers it believes are North Korea-linked after a $285M Drift exploit this week. On Friday, the team posted that it sent Ethereum on-chain messages (“We are ready to speak”) to four wallets holding stolen funds, including a response from one wallet showing $200 worth of ETH.
Drift said it has identified “critical information” about the parties involved, and would share more updates once third-party attributions are completed. Curve Finance founder Michael Egorov said recovery is near zero if the theft is state-sponsored, because such actors typically do not cooperate with negotiations. He noted that recovery becomes much more likely only if the attackers are not tied to state actors.
The wider context: bad-actor attribution remains uncertain, with other experts suggesting possible insider knowledge. Drift previously said the incident stemmed from sophisticated social engineering that enabled attackers to gain administrative control by accessing two private keys. Traders should watch whether the chain-level pursuit leads to any movement on the stolen-fund wallets, since follow-through (or lack of it) can affect sentiment around Solana DeFi security and bridge/perp integrations tied to Drift.
Neutral
该消息更像是“链上沟通与归因推进”,而不是新的资金净流入/净流出信号,因此对整体市场的直接方向性影响有限,偏中性。短期内,Drift exploit 及其背后的社工与私钥暴露指向可能放大 DeFi 与 Solana 生态的风险溢价;类似事件中(例如大型 DeFi 攻击后出现链上追索、归因更新),市场常先承压,等待是否有赃款转移或协议进一步升级/补丁。
但另一方面,Drift 通过以太坊链上向持币钱包发消息,属于“可验证的行动”,若后续出现资金冻结、归还或攻击者让步,会改善风险预期并缓和情绪。若归因指向国家支持团伙,且赃款持续流动,则短期恐慌可能转化为更长周期的监管与安全担忧,间接拖累相关资产表现。
因此:短期更偏情绪扰动,长期取决于(1)第三方归因结果,(2)赃款钱包是否出现可追踪的止损/返还行为,(3)Solana DeFi 是否快速补齐安全流程。当前信息阶段对 BTC/ETH/SOL 等主流资产的方向性影响仍难以确定。