- β’
Drift hack was a six-month social engineering operation
βWhat we learned was... this was a long-term, at least six-month intelligence operation.β
- β’
Attackers used fully constructed identities to build trust
βThey had fully constructed identities, including employment histories, public facing credentials and professional networks.β
- β’
DPRK actors deposited capital to appear legitimate
βThey also deposited $1 million of their own capital.β
- β’
Circle didn't freeze stolen USDC for six hours
βCircle declined to freeze the funds while attackers bridged them across chains for six hours during business hours.β
- β’
Teams must defend against nation-state level threats
βWe have to consider who else might be... being targeted and needs to increase the level of protections they have.β

