Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Solana

    Crypto Lawyer: Drift Incident Could Constitute Civil Negligence

    6 April 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Crypto Lawyer: Drift Incident Could Constitute Civil Negligence
    Crypto Lawyer: Drift Incident Could Constitute Civil Negligence

    The Drift Protocol, a Solana-based decentralized finance platform, is drawing renewed scrutiny after a $280 million exploit exposed persistent gaps in its security posture. A post-incident review and commentary from legal counsel frame the breach as something that could have been prevented with basic operational security measures, prompting discussions about civil negligence and the broader risk landscape facing DeFi projects.

    Attorney Ariel Givner described the scenario as a failure to safeguard user funds, saying, โ€œIn plain terms, civil negligence means they failed their basic duty to protect the money they were managing.โ€ Her assessment followed Driftโ€™s post-mortem detailing how the attack unfolded and how the platform responded. The comments come as critics question the adequacy of Driftโ€™s procedures in a space where attackers frequently rely on social engineering and supply-chain compromises to breach multi-signature setups and other critical controls.

    โ€œEvery serious project knows this. Drift didnโ€™t follow it,โ€ she said, adding, โ€œThey knew crypto is full of hackers, especially North Korean state teams.โ€ Givner continued, โ€œYet their team spent months chatting on Telegram, meeting strangers at conferences, opening sketchy code repos, and downloading fake apps on devices tied to multisignature controls.โ€

    The debate underscores a larger concern: social engineering and project infiltration remain among the most effective attack vectors in crypto, capable of draining user funds and eroding trust in platforms that users otherwise rely on for high-stakes liquidity and yield opportunities.

    Key takeaways

    • Drift Protocol is facing scrutiny over basic security practices after a $280 million exploit, with legal perspectives labeling the incident as civil negligence in light of alleged operational shortfalls.
    • Experts point to missteps such as storing signing keys on non-air-gapped systems and insufficient vendor and developer due diligence, particularly with personnel encountered at conferences.
    • The attackersโ€™ approach reportedly involved months of planning, culminating in targeted social engineering and malware introduced through developer machines.
    • There are signals of a possible link to North Koreaโ€“aligned threat actors, with Drift stating a โ€œmedium-high confidenceโ€ that the same group behind the Radiant Capital hack (October 2024) was involved.
    • Radiant Capitalโ€™s 2024 incident has become part of the narrative tying industry-wide risks to well-known escalation patterns in state-sponsored cyber operations.

    Attack narrative and defensive lessons

    Drift Protocol published an update detailing how the breach unfolded, asserting that the assault was the product of six months of planning. The attackers reportedly approached Drift at a major crypto industry conference in October 2025, signaling interest in potential integrations and partnerships. Over the following months, the bad actors cultivated relationships with Drift developers, ultimately delivering malicious links and embedding malware that compromised the developersโ€™ machines used to manage the protocolโ€™s multisignature controls.

    Driftโ€™s account emphasizes that those involved were not North Korean nationals, though the firm conceded that the threat actors were linked to a broader pattern associated with state-backed cyber campaigns. In a contemporaneous assessment with โ€œmedium-high confidence,โ€ Drift tied the incident to actors believed to have previously orchestrated the October 2024 Radiant Capital hack. Radiant Capital had disclosed that its breach involved malware spread via Telegram from an operator posing as an ex-contractor connected to North Korea. While Driftโ€™s update stops short of confirming a direct line of responsibility, these correlations highlight a persistent threat environment in which sophisticated adversaries leverage social channels to compromise engineering workflows.

    Legal and security observers highlight a recurring theme: even mature crypto teams can underestimate the risk of supply-chain and social-engineering exploits if governance practices do not enforce strict separation between development activities and sensitive credentials. Givnerโ€™s critique goes beyond the specifics of Driftโ€™s incident, pointing to a universal expectation that โ€œair-gappedโ€ signing keys should be kept separate from day-to-day developer work, and that engaging with third-party developers or contractors requires rigorous vetting and ongoing due diligence. In her words, many projects already adhere to these principles because the crypto landscape is โ€œfull of hackers,โ€ and a lapse can be costly both financially and reputationally.

    Industry context: echoes of a broader security paradigm

    The Drift incident arrives as a broader discussion unfolds about how DeFi projects manage risk in a period of heightened adversarial activity. Social engineering, phishing, and malware campaigns targeting developer ecosystems have been repeatedly implicated in high-profile hacks. The Radiant Capital case from late 2024, which involved a North Koreaโ€“linked operator impersonating an ex-contractor to disseminate malware, is frequently cited in security analyses as a cautionary tale about the limits of conventional defensive measures when human factors become the weakest link.

    Industry observers note that the Drift episode reinforces the need for robust governance frameworks around key management, formal vendor assessment processes, and stringent controls on how and where signing keys are stored and used. If the attackers exploited trusted relationships with developers and relied on compromised devices to gain access to multisignature controls, the path to remediation likely involves reinforcing air gaps, implementing hardware security modules for key management, and institutionalizing continuous monitoring and key rotation practices. The emphasis on โ€œdue diligenceโ€ also raises questions about how conferences, hackathons, and third-party collaborations are vetted, and whether drift toward more rigorous third-party risk management will become standard practice across the sector.

    What this means for investors and builders

    For investors, the Drift incident is a reminder that risk management remains a primary driver of platform credibility and capital allocation in DeFi. Projects that can demonstrate resilient onboarding, robust key management, and rigorous vendor scrutiny may distinguish themselves in a market where security shocks can quickly alter perceptions of value and reliability. Builders, in turn, face a delicate trade-off between openness and security. While collaboration and rapid integration are hallmarks of DeFi innovation, the Drift episode suggests that even well-resourced teams must normalize security drills, red-teaming, and clear separation of duties to prevent supply-chain breaches from translating into user losses.

    As regulators and industry groups debate standardized best practices, Driftโ€™s experience could accelerate conversations about mandatory security benchmarks for on-chain protocols, particularly those relying on multi-party computation and multisignature frameworks. In the meantime, users should monitor how Drift and similar platforms respondโ€”through security upgrades, partner vetting, and transparent post-incident reportingโ€”as a practical barometer for the sectorโ€™s willingness to translate rhetoric about security into measurable safeguards.

    Meanwhile, Drift has not publicly detailed its next steps beyond the immediate remediation measures described in its update. The extent to which the platform will overhaul its governance, vendor risk management, and incident response cadence remains to be seen, as does the broader industry adoption of stricter security controls that could alter how quickly and fluidly DeFi protocols can operate with external partners.

    What remains uncertain is how quickly the market will react to these revelations and whether Trust signals built on vulnerability disclosure will translate into a longer-term commitment by users to platforms that publicly address security gaps. For now, the incident underscores a recurring lesson: in DeFi, the difference between resilience and ruin often hinges on the discipline with which teams implement and enforce fundamental security practicesโ€”before a breach, not after.

    As the investigation and remediation continue, market watchers will be paying close attention to Driftโ€™s communications, the evolution of industry security standards, and any subsequent movements by competitors to raise the bar for securing developer environments and signing-key management. The path forward for the sector will be shaped by whether this incident catalyzes meaningful adoption of stronger controls and more rigorous third-party risk governance across the ecosystem.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Bitmine Gains 53,500 Eth, Lifts Stake To 4.9% Of Ethereum Supply

    Bitmine Gains 53,500 ETH, Lifts Stake to 4.9% of Ethereum Supply

    50 minutes ago
    Strive Acquires 1,800 Bitcoin For $143m, Ranks No. 5 Among Firms

    Strive Acquires 1,800 Bitcoin for $143M, Ranks No. 5 Among Firms

    2 hours ago
    Why An Early Bitcoin Holder Burned $1m: Mystery Explained

    Why an Early Bitcoin Holder Burned $1M: Mystery Explained

    3 hours ago
    Bitcoin Price Faces $80,000 Test As Technical And On-Chain Signals Diverge

    Bitcoin Price Faces $80,000 Test As Technical And On-Chain Signals Diverge

    3 hours ago
    Strategyโ€™s First Corporate Bitcoin Buy Tops $370m Since June

    Strategyโ€™s First Corporate Bitcoin Buy Tops $370M Since June

    4 hours ago
    Hyperliquid And Pump.fun Drive 90% Of $638m Record Crypto Buybacks: Ft

    Hyperliquid and Pump.fun Drive 90% of $638M Record Crypto Buybacks: FT

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Crypto Kid Interviews Binance Founder Cz On Financial Freedom And Bitcoin's Future

    Crypto Kid Interviews Binance Founder CZ on Financial Freedom and Bitcoin’s Future

    7 August 2026

    Latest News

    • Bitmine Gains 53,500 ETH, Lifts Stake to 4.9% of Ethereum Supply
    • Strive Acquires 1,800 Bitcoin for $143M, Ranks No. 5 Among Firms
    • Why an Early Bitcoin Holder Burned $1M: Mystery Explained
    • Bitcoin Price Faces $80,000 Test As Technical And On-Chain Signals Diverge
    • Strategyโ€™s First Corporate Bitcoin Buy Tops $370M Since June
    • Hyperliquid and Pump.fun Drive 90% of $638M Record Crypto Buybacks: FT
    • Bitcoin Weekly Brief: Markets Price September Fed Hikeโ€”5 Key Takeaways
    • Blockaid Flags $9.3M Lending Reserve Drain via Ankr Tokens, E-Mode
    • Blockaid Reports $9.3M Lending Reserve Depleted Across More Markets
    • Bitcoin Upgrades with Quantum-Ready Security; 18.9M SOL Stopped

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Bitpanda
    Tangem 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Crypto.com
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!