Home > Quick > Body

Human Error Remains a Major Security Risk in DeFi Attacks, SlowMist Says

clock
2026-07-24 08:03:21
Foresight News posted on X (formerly Twitter). Human error remains one of the biggest security vulnerabilities in crypto, according to the report, which cited the theft from Solana-based perpetuals platform Drift Protocol as a prominent example. In autumn 2025, a group claiming to be from a quantitative trading firm contacted the Drift team, traded more than $1 million on the platform, and participated in community discussions for six months to build trust.

On April 1, 2026, the group reportedly persuaded one of the multisig signers, who control contract funds, to pre-sign a hidden authorization in what appeared to be a normal transaction. Within 12 minutes, about $285 million in user assets was transferred out. Later investigations attributed the attack to UNC4736, a threat group linked to the North Korean government that has targeted the crypto and fintech sectors since 2018 through supply-chain attacks, social engineering, and malware delivery. Its known major incidents include the 2023 3CX supply-chain attack, the theft of about $50 million from Radiant Capital in 2024, and the Drift theft, bringing the group's total known stolen funds to about $335 million based on the figures cited.

The report said operational security failures appeared frequently in the first half of the year across key management and infrastructure layers. It cited an attack on Kelp DAO that involved a compromise of third-party RPC infrastructure used by the project, allowing attackers to forge cross-chain message verification and transfer about $291 million. It also cited Resolv Labs, which underwent 18 security audits before losing about $26.85 million after its AWS cloud key management service was breached. In mid-July, a security incident at @Ostium caused losses of more than $23.75 million after an administrator account private key was exposed, allowing intruders to access off-chain infrastructure tied to the protocol's price system.

SlowMist, along with @SlowMist_Team, @evilcos, and @im23pds, has tracked North Korea-related threat groups for years and said social engineering tactics are shifting from quick access grabs to long-term trust building, making attacks longer, more resource-intensive, and harder to detect. The report also said the crypto industry still lacks a common operational security standard. It noted that many teams still treat security as a one-time code audit before launch, while key management, access separation, and employee security awareness remain underinvested.

Some mature projects have built more complete security systems, but many small and midsize teams still lack basic multisig setups and key rotation. SlowMist's security team placed key management first in its minimum operational security standard for DeFi projects, saying critical assets and management permissions should use multisig structures and formal key generation, storage, backup, and rotation procedures. The team said operational security is fundamentally about people, and that the main change in Web3 security in the first half of the year has been a shift from code vulnerabilities to attacks on people and processes. As social engineering attacks grow more sophisticated, project teams need continuous security training and attack-defense exercises to improve their ability to recognize phishing, AI-generated content, and other new attack methods.
Disclaimer:
1. The information provided does not constitute investment advice. Investors should make independent decisions and bear all risks themselves.
2. The copyright of this content belongs to the original author. The views expressed herein are solely those of the author and do not represent the stance or position of this website.
New Tab Page - Desk3 | Plugin
Stay ahead of the game in the cryptocurrency space.