The U.S. Department of the Treasury expands cyber security intelligence, and encrypted companies receive traditional finance–level protection

DRIFT-1,16%
RDNT-0,31%

網路安全威脅

The U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP) announced Thursday that it is expanding the coverage of its cyber threat identification program to digital asset companies. Blockchain firms that choose to join will “receive” the same level of cyber threat intelligence as traditional financial institutions for free. In 2026 Q1, cumulative losses from hacker attacks suffered by decentralized finance (DeFi) platforms are approaching $169 million.

OCCIP Program Breakdown: Blockchain Companies Can Get Threat Intel for Free

The core of this expansion is bringing the cryptocurrency industry into the cyber threat identification framework that previously covered only traditional financial institutions. According to the Treasury Department’s announcement, participating blockchain companies will receive threat intelligence services at the same level as traditional financial institutions such as banks and securities firms—and at no cost.

The background to this policy is that the cryptocurrency industry has long operated outside regulatory frameworks and lacks systematic government threat intelligence support. As a result, when facing attacks from foreign intelligence agencies and organized crime groups, it often has to rely only on its own security resources. This move by the Treasury Department marks a shift in how the U.S. government categorizes cybersecurity for the digital asset industry—from peripheral financial activities to critical financial infrastructure that requires systematic protection.

Threats Escalate: Drift Protocol Reveals North Korea’s Full Playbook for Infiltrating Crypto

加密產業駭客攻擊 (Source: TRM Labs)

The urgency of the Treasury Department’s expanded protection program is made clear by a series of recent major attack incidents. This month, the decentralized exchange Drift Protocol suffered an attack totaling $280 million, and the attackers are believed to be connected to North Korea.

North Korea’s Infiltration Pattern Exposed by the Drift Protocol Attack

Social engineering intrusion: The attackers initially made in-person contact with the Drift team at a large cryptocurrency industry conference, establishing a “reasonable” initial relationship.

Long-term infiltration: In the months after the first meeting, the attackers continued interacting with the Drift team, gradually building trust.

Malware implantation: After months of relationship maintenance, the attackers successfully deployed malware designed to steal cryptocurrency on the machines of Drift developers.

Scheduled activation of the attack: The malware was activated during an April vulnerability incident, leading to $280 million in losses.

Man-in-the-middle cover: Reports indicate that the person who initially reached out to the Drift team was not a North Korean national, suggesting the attackers used a third-party intermediary as a cover.

Seals911, a blockchain network cybersecurity expert team, said they have a “moderate-to-high level of confidence” that this attack is linked to the October 2024 Radiant Capital hacker incident as part of the same organization. The North Korea-linked Lazarus Group is believed to be associated with multiple similar attacks.

Policy Background: Closing the Long-Standing Security Gap in the Crypto Industry

The policy basis for the Treasury Department’s action comes from the report issued by the Trump administration in July 2025, titled “Strengthening U.S. Leadership in the Digital Financial Technology Sector.” The report explicitly lays out the policy direction of including digital asset companies within the federal cybersecurity protection framework.

In terms of threat scale, TRM Labs’ data shows that cumulative losses from cryptocurrency hacker attacks between 2022 and 2025 have been enormous. And the $169 million DeFi loss in 2026 Q1 shows that attack frequency and scale have not declined despite regulatory pressure. The rollout of this Treasury Department plan represents a systematic action by the U.S. on cybersecurity policy for crypto networks, not merely a temporary measure in response to a single incident.

Frequently Asked Questions

What specific protections does the U.S. Treasury’s cyber threat intelligence program provide to crypto companies?

According to the Treasury Department’s announcement, blockchain companies that join the program will receive cyber threat intelligence at the same level as traditional banks and securities firms for free, including real-time threat identification, analysis of attack methods, and risk alerts. This helps crypto companies identify and prevent cyberattacks targeting their platforms in advance.

How does North Korea’s Lazarus Group attack cryptocurrency companies?

Based on the pattern revealed in the Drift Protocol attack incident, North Korea-linked groups typically use long-term social engineering tactics: first, establish contact relationships at industry events, then build trust through months of interaction, and finally implant malware on the target developers’ devices, waiting for the right moment to trigger it. This approach is far more covert than direct technical exploitation of vulnerabilities.

Does this Treasury Department action mean the crypto industry is officially being included in the protection framework for critical financial infrastructure?

The rollout of this expanded program signifies that the U.S. government, at the policy level, is bringing the digital asset industry within the scope of financial infrastructure that needs systematic protection. The policy recommendations from the Trump administration’s July 2025 report have been implemented in practice, showing that the U.S. is proactively closing the institutional gap left by the long-term lack of federal cybersecurity support for the crypto industry.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

France: More than 40 crypto investor kidnappings in 2026, involving leaked tax data

According to Market Forces Africa, reported on April 27, incidents of kidnapping and violent attacks targeting cryptocurrency investors in France have increased sharply. On the X platform, Telegram founder Pavel Durov said that since the beginning of 2026, he has recorded 41 cases of cryptocurrency investor kidnappings, averaging one incident every 2.5 days, and that they are linked to a leak of French tax records.

MarketWhisper3m ago

Chainalysis: EU's New Sanctions on Russia Mark 'a New Era' of Crypto Enforcement

The blockchain intelligence agency highlighted that the recently issued sanctions package against Russia was perhaps the most comprehensive crypto-focused action by the EU, targeting the whole Russian cryptocurrency sector rather than individual actors, including the digital ruble in full and the

Coinpedia6m ago

IMF's Former Chief Economist Warns Double Deregulation Could Trigger Systemic Financial Crisis

Gate News message, April 27 — Kenneth Rogoff, former chief economist of the International Monetary Fund, has warned that the Trump administration's push for financial deregulation—particularly loosening bank capital requirements and regulatory transparency—is significantly raising the risk of a

GateNews1h ago

U.S. and Iran Moving Toward Diplomatic Resolution Framework, Gulf States Demand Inclusion

Gate News message, April 27 — According to Al Jazeera, diplomatic sources indicate that recent developments have reinforced the need for the United States and Iran to permanently end their adversarial relationship, with various parties gradually approaching a framework that could enable a

GateNews2h ago

U.S.-Iran talks collapse triggers a sharp drop in gold prices, while Bitcoin quickly surges past $79k

Bitcoin rose above $79,000 during the Asian trading session on April 27. At the same time, the spot gold price fell to a low of $4,672.11 per ounce, with an intraday decline of more than $38. The backdrop is that U.S. President Trump canceled the itinerary of his special envoy to Islamabad, Pakistan, and the U.S.-Iran peace negotiations have hit a stalemate. Federal Reserve Chair Powell is scheduled to preside over his final news conference of his tenure at the Federal Open Market Committee (FOMC) on April 29.

MarketWhisper2h ago

Bitcoin and Asian Equities Rally Amid Easing Geopolitical Tensions

Gate News message, April 27 — Bitcoin and Asian equities rose in tandem on April 27, driven by easing geopolitical tensions. Bitcoin gained 2% over the past 24 hours to $79,110, while Ethereum climbed 3% to $2,388. Asia's major stock indices posted strong gains on Monday morning: Japan's Nikkei 225

GateNews3h ago
Comment
0/400
No comments