Ripple says it will share North Korea-linked threat intelligence with crypto companies as the industry faces changing hacking tactics. The announcement follows major incidents involving the Drift breach, widely reported as a roughly $280–$285 million exploit in April, along with another large DeFi protocol attack involving KelpDAO. Multiple outlets describe the April attacks as part of a broader pattern attributed to DPRK-linked actors that is increasingly focused on long-cycle social engineering rather than conventional smart-contract exploit methods.
According to the reports, Ripple’s analysis indicates that attackers are adapting their approach by combining prolonged infiltration or manipulation processes with credential- and access-based techniques, which can be harder for teams to detect using purely technical defenses aimed at smart contracts. Ripple frames the information-sharing effort as a way to help crypto firms better recognize and respond to these emerging threats. The details of what specific indicators or mitigation guidance will be provided are not included in the summaries, but the common theme across sources is that the threat landscape is shifting and that intelligence sharing is intended to support prevention and incident response across the sector.