Drift Protocol’s published investigation into the theft said the attack was a long-running, organized infiltration campaign that lasted about six months, with the attackers allegedly first contacting the team at a major crypto conference in October 2025 while posing as a quantitative trading firm. Drift said it linked the attackers with medium-high confidence to the October 2024 Radiant Capital hack. Lawyer Ariel Givner said the exploit, described in the new report as involving roughly $280 million, could have been prevented through standard operational security procedures. The existing report described the theft as $285 million, while the latest update cites about $280 million.