On April 1, 2026, attackers drained approximately $285 million from Drift Protocol — Solana's largest decentralized perpetual futures exchange — in roughly 12 minutes. The exploit combined social engineering of multisig signers, abuse of Solana's "durable nonce" transaction feature, and oracle ma...
"Circle was asleep while many millions of USDC were swapped via CCTP from Solana to Ethereum for hours from the 9-figure Drift hack during US hours." — ZachXBT, On-Chain Investigator
On April 1, 2026, attackers drained approximately $285 million from Drift Protocol — Solana's largest decentralized perpetual futures exchange — in roughly 12 minutes. The exploit combined social engineering of multisig signers, abuse of Solana's "durable nonce" transaction feature, and oracle manipulation via a fabricated token. Drift's total value locked collapsed from $550 million to under $250 million within hours. The DRIFT governance token fell 40%.
Blockchain analytics firms TRM Labs and Elliptic have independently flagged the attack as consistent with North Korean state-sponsored hacking operations, potentially linking it to the same actor group behind the $1.4 billion Bybit exploit in February 2025. If confirmed, it would be the 18th DPRK-attributed crypto theft tracked in 2026. The incident also triggered a secondary controversy: Circle, issuer of USDC, failed to freeze $232 million in stolen stablecoins bridged through its own Cross-Chain Transfer Protocol over a six-hour window during U.S. business hours.
This report examines the attack vector, its systemic implications for DeFi governance infrastructure, and the widening gap between stablecoin issuers' compliance capabilities and the speed at which stolen funds move on-chain.
The exploit did not originate from a smart contract vulnerability. It was a governance takeover executed through social engineering and pre-signed administrative transactions.
Pre-staging (March 11–30): On-chain records show the attacker withdrew 10 ETH from Tornado Cash on March 11. Activity resumed hours later, around 09:00 Pyongyang time on March 12, according to TRM Labs. Between March 23 and March 30, the attacker created multiple "durable nonce" accounts on Solana — a legitimate feature that allows transactions to be pre-signed and submitted at any future point without expiration.
Multisig compromise: The attacker used social engineering to induce members of Drift's five-person Security Council multisig into pre-signing transactions that appeared routine but contained hidden authorizations for critical admin actions. With two misleading approvals secured, the attacker held pre-signed transactions that remained valid indefinitely.
Execution (April 1): Drift ran a legitimate test withdrawal from its insurance fund. Approximately one minute later, the attacker submitted the pre-signed durable nonce transactions. Two transactions — four slots apart on the Solana blockchain — were sufficient to create and approve a malicious admin transfer, then approve and execute it. Within minutes, the attacker held full control of Drift's protocol-level permissions.
Drain (12 minutes): The attacker listed a fabricated token — CarbonVote Token (CVT) — as valid collateral on Drift, removed all withdrawal limits, deposited hundreds of millions of CVT as collateral, and executed 31 rapid withdrawals. Stolen assets included USDC, SOL, JLP, wrapped BTC, JTO, and Fartcoin (FRT). The entire drain took approximately 12 minutes.
Bridging (6 hours): Approximately $232 million in stolen USDC was bridged from Solana to Ethereum via Circle's Cross-Chain Transfer Protocol (CCTP) across 100+ transactions over six consecutive hours — all during U.S. business hours.
Standard Solana transactions include a "recent blockhash" — a timestamp that expires after 60 to 90 seconds, preventing old transactions from being replayed. Durable nonces override this safety mechanism by replacing the expiring blockhash with a fixed one-time code stored in an on-chain account, keeping the transaction valid indefinitely until submitted.
This feature exists for legitimate purposes: offline signing workflows, scheduled transactions, and multisig coordination where signers cannot all be online simultaneously. According to CoinDesk, the durable nonce vector is "particularly dangerous because it exploits a feature that exists for good reason and is difficult to defend against without fundamentally changing how multisig approvals work on Solana."
The attacker weaponized this by collecting pre-signed approvals over a multi-week period, then executing them in a single coordinated burst. The signers who approved the transactions had no visibility into when — or in what context — their approvals would ultimately be used.
Ledger CTO Charles Guillemet drew a direct parallel to the Bybit hack: "Drift's $230M hack looks like Bybit all over again." In February 2025, Lazarus Group compromised Bybit's multisig by targeting individual signers' machines. The Drift attack followed a nearly identical pattern — targeting the human layer rather than the code layer.
Three weeks prior to the exploit, the attacker minted 750 million units of a fictitious token called CarbonVote Token (CVT) on Solana. The attacker seeded approximately $500 in liquidity on Raydium and conducted wash trading over several weeks to generate a stable price history near $1.
Drift's oracle infrastructure treated CVT's fabricated price feed as legitimate. Once the attacker gained admin control of the protocol, CVT was listed as valid collateral. The attacker deposited hundreds of millions of CVT tokens — valued at near-zero real cost — and withdrew real assets against this phantom collateral.
This vector exposed a structural weakness in oracle validation: the absence of minimum liquidity thresholds, trading volume verification, or asset-listing governance checks that could flag a near-worthless token being listed as collateral backing hundreds of millions in real assets.
Both TRM Labs and Elliptic flagged the exploit as bearing hallmarks of DPRK-linked operations.
TRM Labs' indicators:
Elliptic's assessment: "The on-chain behavior, laundering methodologies, and network-level indicators associated with the attack are consistent with techniques observed in previous DPRK-attributed operations," including the $1.4 billion Bybit exploit.
If confirmed, the Drift hack represents the 18th DPRK crypto theft tracked in 2026 and the second-largest single DeFi exploit in Solana's history, behind only the $326 million Wormhole bridge hack in February 2022.
DPRK-linked entities have now been attributed to over $3 billion in cumulative crypto theft since 2017, per U.S. government and blockchain analytics estimates. The operational sophistication has escalated from phishing campaigns targeting exchange employees to multi-week social engineering operations targeting protocol governance structures.
The Drift hack amplified an ongoing controversy over Circle's compliance response times. The attacker bridged $232 million in stolen USDC from Solana to Ethereum via Circle's own CCTP over six hours during U.S. business hours. Circle did not freeze the funds during this window.
ZachXBT documented the timeline publicly, noting that Circle had proactively frozen 16 unrelated corporate hot wallets tied to a sealed U.S. civil case on March 23 — just nine days before the Drift hack. The investigator cited 15 cases involving over $420 million in total where Circle's freeze response was delayed or absent.
Circle's defense: the company stated it freezes assets "when legally required," citing potential legal liability for freezing assets without court or law enforcement orders. According to Financial Magnates, Circle "defended its limited role, citing legal boundaries."
The tension is structural. Stablecoin issuers hold centralized freeze capabilities by design — Circle can blacklist any USDC address — but exercising that power without legal authorization raises questions about due process, liability, and whether a private company should act as an unilateral enforcement mechanism. The six-hour gap nonetheless raises questions about whether automated monitoring systems should flag anomalous CCTP flows — particularly 100+ transactions from flagged addresses within a single session.
The impact extended beyond Drift. According to reporting from Ainvest, the initial $280 million drain triggered a cascade directly impacting an estimated 11 DeFi projects across the Solana ecosystem. Drift's TVL collapsed from approximately $550 million to under $250 million. The DRIFT token fell 37%–42% in the hours following the exploit, bottoming near $0.04–$0.05.
Drift suspended all deposits and withdrawals. The protocol's insurance fund — designed to cover losses from liquidation shortfalls — was withdrawn from the protocol and moved to a separate environment for safeguarding, according to the Drift team. A full post-mortem and compensation plan remain pending as of April 4.
The exploit is the second major multisig-related security failure on Solana in 2026, following the $40 million Step Finance private key compromise in January.
According to DefiLlama, DeFi protocols lost $168.6 million to hacks across 34 protocols in Q1 2026 — an 89% decline from the $1.58 billion stolen in Q1 2025 (which included the $1.4 billion Bybit exploit). The Drift hack, occurring on April 1, was not included in Q1 totals.
Including Drift, Q1+early-Q2 2026 losses exceed $450 million. Drift alone accounts for approximately 63% of that figure.
Largest DeFi exploits, 2026 YTD:
| Incident | Date | Amount | Vector | |---|---|---|---| | Drift Protocol | April 1, 2026 | $285M | Multisig social engineering + oracle manipulation | | Step Finance | January 2026 | $40M | Private key compromise | | Truebit | January 8, 2026 | $26.4M | Smart contract manipulation |
The pattern is notable: the two largest exploits of 2026 targeted governance and key management infrastructure — not smart contract code. This reflects a broader trend identified by multiple security firms: as smart contract auditing has matured, attackers have shifted focus to the human and governance layers.
The Drift exploit is not a novel attack in concept. It follows the same playbook as the $1.4 billion Bybit hack: target the signers, not the code. The escalation is in execution — a multi-week social engineering campaign, abuse of a legitimate Solana feature for transaction persistence, and fabrication of an entire token ecosystem to manufacture fake collateral.
The systemic questions the incident raises are concrete. First, whether Solana's durable nonce feature requires protocol-level safeguards — such as mandatory expiration windows or signer-notification mechanisms — to prevent weaponization against multisig governance. Second, whether stablecoin issuers' compliance infrastructure can operate at the speed of on-chain fund movement, or whether a structural six-hour gap between exploit and response is the permanent baseline. Third, whether oracle systems require hard-coded minimum liquidity and trading volume thresholds before accepting any asset as valid collateral.
DeFi's security perimeter has shifted. Code audits remain necessary. They are no longer sufficient. The attack surface is now the governance layer — the humans who hold the keys, the processes that validate their signatures, and the infrastructure that monitors anomalous on-chain behavior in real time.