I'm a DPRK Soldier

An imaginative first-person retelling of the Drift Hack incident

Photo by US Air Force / James Mossman

I’m a DPRK soldier assigned to Lazarus Group, or - way more boringly - the General Reconnaissance Bureau, 3rd Bureau, Unit 121. I hacked Drift Protocol for $285 million on April Fool’s Day. The day was a coincidence, but we got a good chuckle out of it around the office. You steal when the stealing is good, not always on a schedule. But we cracked jokes all day about the Americans first learning about it, then hoping it was a joke, then realizing it was real. We bathed in capitalist tears. The vibes were immaculate.

There are many other comrades like me. I see Westerners talk about Lazarus Group in the media as though we’re just a small team because they just can’t intuitively grasp the scale. They don’t imagine several office complexes; dozens of satellite offices; teams collaborating across time zones; and operations, analysis, and capabilities development organizations. We don’t care if they don’t understand though; it’s better that way.

We only got to actually enjoy the afterglow for 17 days - until the Ethereum team beat us by ~$5 million dollars with the KelpDAO exploit. The Solana team is smaller and hasn’t posted the same results, so we still have something to prove. They’re the big dogs on the block and have been at it for years. So it was pretty deflating when Corporal Kim (actually, they’re mostly named Corporal Kim) trotted up to our floor with a shit-eating grin two weeks later. “Guess who’s going to be the most productive labor unit this month?” he asked. Fuck those guys, assholes. Of course, they screwed it up and got frozen on Arbitrum and lost part of the People’s money. Who’s laughing now, Corporal Kim?

Part of our job is to monitor what the Western press says about us. It gives is a rough idea of what intelligence services know about us, and a much better proxy for what our actual targets know about us - since they don’t have access to intelligence. I like the Risky Business podcast for this job. They’re detailed enough to be accurate most of the time and call balls and strikes pretty fairly. They have a recurring joke about whether they “gotta hand it to us.” They did this time.

They dedicated a podcast to my work specifically, or rather, my team’s work. “Between Two Nerds: Hackers from the future.” That got some backslaps around the office the day it dropped. The Grugq and Tom Uren walked through the mechanics of the operation. They were mostly working from Drift’s public incident summary, so obviously there’s a lot they can’t know, but they also exposed a little misunderstanding of specific crypto mechanics.

The thing that struck me was their analysis at the end, when Grugq suggests that we may be inevitable. I’d rate this “partly true.” With intelligence gathering operations, if your target is the only one with the access or information you need, you must get that target. Full stop. You keep working on it until you succeed or priorities change. Our mission is a little different. We are tasked with getting money to fund other programs. Money can be found in a lot of places.

Most of the online discourse is pretty brain-dead and focuses on the wrong things. “Drift should have done this, they should have done that.” There is no magic bullet. A lot of people approach this with a fundamental misunderstanding. This isn’t a solo game; there’s another player on the board. That is us. Whatever you do, we will adapt. We will have meetings. We will devise plans. We will make new tools. We will find a way. The fact that few understand this is a great benefit to the Democratic People’s Republic.

Grugq’s argument about the keys is perfectly true; if the multi-sig had been 3 of 7 or 4 of 9 or some stronger configuration, we’d have just gotten the other needed keys. We had deep access. We had breached the trust perimeter. That’s the most important part.

But we’re not immune to cost-benefit analysis. Powerpoints are too capitalist-coded. We don’t do them. But we do have meetings. In the meetings we report metrics. The worker’s labor hours are sacred and must be directed to the most appropriate ends. We have an overarching mission to get money. We achieve this directive by using worker’s labor hours. We maximize outcomes per labor hour. As the Dear Leader as decreed. Right now, the maximum outcome is stealing crypto.

We’ve done a lot of things to achieve our mission: we’ve laundered money, we’ve sold drugs, we’ve smuggled goods, we’ve counterfeited money, we’ve attacked the SWIFT network. All of those were good strategies, for a time. They were local optima for achieving the mission. Now that is crypto.

What Risky Businhess didn’t say is that you can actually make it hard enough that the investment of workers’ hours doesn’t pencil out. We have a lot of comrades on this project though - a lot. We have training pipelines, playbooks, tools. We have a deep well of skills and experience. We may pass on your specific protocol, but we will target someone else in crypto because that is currently what we are tooled to do. And it works.

It may not pencil out some day. If crypto heists start repeatedly failing true labor-cost accounting, we may have to shift focus. Only then will the budgets get reassigned to other activities. The training pipelines will narrow, the toolkits will go stale for lack of staff maintaining them, the skills will atrophy. This will take years.

What is true is that Drift was probably game-over after month two. Maybe they missed some red flags, but we try not to give any. We have meetings about this. The meetings result in plans. The plans are executed by professional operators. But I don’t know, I didn’t see it from their side. There is always a giddy moment when you realize it’s actually working. That you know the mark doesn’t know they’re the mark. That came pretty early for Drift.

We’ve had other operations that didn’t work. We always spend some of our time on the lookout for the next target. We probe gently at first. If resistance feels soft we have a meeting. We present the metrics. What can we get? How many of the comrades’ labor hours do we project we will expend? We do the math. If the math checks out, we begin.

So here’s my advice. If you don’t want to get hacked, don’t have access to a lot of money. If you can’t do that part right, then you’d better get ready. Security is not a one-time event. “We secured the keys. We audited the code. We’re done.” This is not how it works. Security is a forever obligation. Cyberspace is a battlefield whether you know it or not. It’s better for me if you don’t.