Crypto Under Siege: A Dozen Protocols Targeted in Two-Week Hack Spree Following Drift's $280M Exploit
The crypto ecosystem is experiencing a coordinated assault. At least 12 DeFi protocols and crypto businesses have been compromised in just over two weeks since the catastrophic $280 million Drift Protocol exploit on April 1—and the velocity isn't slowing down.

The crypto ecosystem is experiencing a coordinated assault. At least 12 DeFi protocols and crypto businesses have been compromised in just over two weeks since the catastrophic $280 million Drift Protocol exploit on April 1—and the velocity isn't slowing down.
The hit list reads like a security audit nightmare: CoW Swap, Hyperbridge, Bybit, Dango, Silo Finance, BSC TMM, Aethir, MONA, Zerion, and most recently Rhea Finance and the Grinex exchange. Each represents another data point in what's become a disturbing trend of systematic targeting across the crypto trading and DeFi landscape.
The Drift Protocol Catalyst
Drift Protocol's April 1 incident remains the catalyst—a $280 million long-running social engineering attack linked to North Korean-affiliated actors. That breach appears to have either exposed vulnerabilities or emboldened threat actors. What started as one mega-exploit has morphed into an industry-wide vulnerability showcase.
Recent Attacks: Rhea Finance and Grinex Lead the Charge
Rhea Finance took a $7.6 million hit through a coordinated pool manipulation attack targeting its Margin Trading feature, according to CertiK analysis. The attacker's playbook was sophisticated: create fake token contracts, inject liquidity into fresh pools, and exploit oracle and validation layer gaps. It's textbook DeFi protocol penetration.
Meanwhile, the Russia-linked Grinex exchange suffered a $13.7 million hack and suspended operations, blaming "unfriendly states"—a geopolitical deflection that underscores the international nature of these attacks.
The combined $21 million from these two incidents alone signals we're beyond isolated incidents. This is coordinated targeting.
The Broader April Casualties
BSC TMM/USDT liquidity pool lost $1.67 million to reserve manipulation in early April. Bridge aggregator Dango hemorrhaged $410,000 from a smart contract bug on April 13. Silo Finance lost $392,000 to a misconfigured oracle exploit on April 3. Aethir, a decentralized GPU computing platform, lost $423,000 to an access control vulnerability on April 9.
These aren't headline-grabbing figures individually, but collectively they represent a systematic dismantling of protocol security infrastructure.
The AI-Powered Threat Evolution
What makes this wave particularly concerning: North Korean-affiliated groups are weaponizing AI and social engineering alongside traditional technical exploits. The Drift Protocol and Zerion wallet cases demonstrate how credential theft through AI-assisted social engineering precedes actual fund extraction.
This isn't random. DefiLlama data shows malicious actors extracted over $168.6 million from 34 DeFi protocols in Q1 2026 alone. The sophistication is escalating as advancing AI models—like Anthropic's Claude—lower the technical barrier for social engineering attacks.
Alpha Take
We're witnessing the transition from opportunistic hacks to coordinated campaigns. The Drift Protocol exploit didn't just result in a $280 million loss; it became a playbook. For traders and portfolio managers, this means treating DeFi protocol security as a core risk metric, not an afterthought. Diversification across audited, battle-tested platforms and reducing exposure to newly launched or recently upgraded protocols should be non-negotiable in your crypto risk management framework. The market intelligence here is clear: assume every protocol is under active reconnaissance.
Originally reported by
CoinTelegraph
Not financial advice. Crypto investing involves significant risk. Past performance does not guarantee future results. Always do your own research.