On April 1, 2026, attackers drained $285 million from Drift Protocol — Solana's largest perpetual futures DEX — in 12 minutes. The exploit was not a smart contract vulnerability. It was the culmination of a six-month social engineering campaign attributed with medium-high confidence to UNC4736, a...
"Circle was asleep while many millions of USDC were swapped via CCTP from Solana to Ethereum for hours from the 9-figure Drift hack during US hours." — ZachXBT, Blockchain Investigator
On April 1, 2026, attackers drained $285 million from Drift Protocol — Solana's largest perpetual futures DEX — in 12 minutes. The exploit was not a smart contract vulnerability. It was the culmination of a six-month social engineering campaign attributed with medium-high confidence to UNC4736, a North Korean state-affiliated hacking group also tracked as AppleJeus and Citrine Sleet.
The attackers manufactured a fictitious token, manipulated oracles into treating it as legitimate collateral, and used a legitimate Solana feature — durable nonce accounts — to pre-sign administrative transactions weeks before execution. DRIFT token fell 42% to an all-time low of $0.033. Protocol TVL collapsed from $550 million to $232 million. SOL dropped 5.5% within hours.
The fallout extends well beyond Drift. Circle faces a class-action investigation for failing to freeze $232 million in stolen USDC that traversed its own bridge infrastructure over six hours during U.S. business hours. The Solana Foundation launched the STRIDE security program on April 6. Drift floated an IOU airdrop compensation plan that drew immediate backlash. The incident exposes structural governance failures in DeFi that no amount of code auditing can address.
At approximately 12:00 UTC on April 1, 2026, attackers executed 31 rapid withdrawals from Drift Protocol's vaults, draining approximately $285 million in USDC, JLP, SOL, and other tokens. The entire extraction took roughly 12 minutes, according to TRM Labs.
The critical vulnerability was a compromised multisig governance structure. On March 27, Drift had migrated its Security Council to a new 2-of-5 threshold configuration with zero timelock — eliminating the mandatory delay that would have allowed detection and intervention before administrative actions took effect. The attacker had already obtained the required two-of-five approval threshold through social engineering.
Stolen assets were consolidated and swapped into USDC and SOL. According to Elliptic, the majority was bridged from Solana to Ethereum using Circle's Cross-Chain Transfer Protocol (CCTP) in more than 100 separate transactions over approximately six hours. On Ethereum, portions were converted into ETH, while some funds moved through centralized exchanges.
This is the largest DeFi exploit of 2026 and the second-largest security incident in Solana's history, behind only the $326 million Wormhole bridge hack in February 2022.
According to Drift's post-incident report published April 6, the operation began in the fall of 2025. Operatives posing as a quantitative trading firm initiated contact with Drift contributors. Over six months, the attackers built working relationships with multiple team members, meeting face-to-face at several major industry conferences across different countries in February and March 2026, according to reporting by The Hacker News and Gizmodo.
The attack is attributed with medium-high confidence to UNC4736, also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces. This is the same group linked to the $50 million Radiant Capital hack in October 2024, as identified by Mandiant.
The attackers compromised contributor devices through a malicious code repository and a fake TestFlight application. With device access, they induced multisig signers into pre-signing transactions that appeared routine but carried hidden authorizations for critical admin actions, according to CoinDesk.
Between March 23 and March 30, the attacker created multiple durable nonce accounts — a legitimate Solana feature that allows transactions to be pre-signed and executed later without expiring. According to BlockSec's analysis, four durable nonce accounts were created: two associated with Drift Security Council multisig members and two associated with attacker-controlled accounts. On March 30, a new durable nonce account appeared tied to a member of the updated multisig, confirming the attacker had re-obtained the required signing threshold under the new 2-of-5 configuration.
The attacker created a fictitious token called CarbonVote Token (CVT), minting approximately 750 million units, according to TRM Labs. The attacker controlled more than 80% of the supply. On-chain staging began on March 11 with a 10 ETH withdrawal from Tornado Cash.
The attacker seeded a liquidity pool on Raydium with approximately $500 and used wash trading — buying and selling between their own wallets — to build a fake price history near $1 per token. Drift's oracles treated CVT as legitimate collateral worth hundreds of millions of dollars.
Using the inflated CVT position as collateral, the attacker executed the 31 rapid withdrawals, draining real assets — USDC, JLP, SOL, and other tokens — from Drift's vaults.
The most contentious aspect of the aftermath centers on Circle Internet Financial. According to blockchain investigator ZachXBT, approximately $232 million in stolen USDC was bridged from Solana to Ethereum via Circle's CCTP over six hours during U.S. business hours. Circle took no action to freeze the funds.
The backlash intensified because of a contrasting precedent. According to ZachXBT, nine days before the Drift hack, Circle had frozen 16 business wallets in a separate civil matter — including DFINITY Foundation's ckETH Minter contract — demonstrating both the capability and willingness to freeze assets. Five of those wallets were later unfrozen.
Circle has stated it freezes assets when legally required, citing potential legal liability from unauthorized freezes. According to ZachXBT's broader investigation published after the incident, he identified 15 cases totaling more than $420 million in illicit USDC flows that Circle failed to freeze promptly since 2022.
The immediate market impact was severe:
On April 6, the Solana Foundation and Asymmetric Research launched STRIDE (Solana Trust, Resilience and Infrastructure for DeFi Enterprises), a tiered DeFi security program, according to CoinDesk.
The program's structure, as reported:
The Foundation also launched the Solana Incident Response Network (SIRN), a coalition including Asymmetric Research, OtterSec, Neodyme, Squads, and Zeroshadow for real-time crisis response.
A critical limitation, acknowledged by multiple security researchers: STRIDE's formal verification and on-chain monitoring would not have caught this attack. The transactions were valid by design — legitimate administrative actions executed via properly authorized multisig signers — and indistinguishable from routine operations until the vaults were emptied.
On April 7, Gibbs Mura, A Law Group announced a class-action investigation on behalf of Drift investors, according to Business Wire. The investigation focuses not on the hackers but on potential claims against Circle Internet Financial for its alleged failure to act despite having the technical ability, contractual authority, and operational precedent to freeze the stolen USDC.
Separately, a legal expert quoted by The Coin Republic on April 7 characterized the incident as a potential civil negligence case against Drift's operators, citing the zero-timelock Security Council migration as a governance failure that removed a critical safeguard.
Solana co-founder Anatoly Yakovenko publicly suggested that Drift could survive by issuing IOU tokens — an "airdrop" to affected users with the core engineering team rebuilding the platform and using the tokens to eventually make users whole. The model mirrors Bitfinex's approach after its $72 million hack in 2016, as reported by Yahoo Finance.
The proposal faced immediate criticism. Analysts argued that describing the issuance as an "airdrop" obscures the core issue: without a solvent protocol and a viable path to repayment, the tokens carry no intrinsic value beyond speculation on future recovery, according to BeInCrypto.
The Drift team's deposit of 56.25 million DRIFT tokens to centralized exchanges during the crisis compounded skepticism about the viability of any internal compensation plan.
The Drift exploit fits within a pattern of accelerating North Korean crypto theft. According to data compiled by Chainalysis and Elliptic:
The Drift attack shares the same operational signature as the October 2024 Radiant Capital hack: extended social engineering, compromised devices, multisig manipulation, and rapid fund extraction.
The Drift Protocol exploit demonstrates that the primary attack surface in DeFi has shifted from smart contract code to governance and human operations. Drift's contracts passed audits. Its code was sound. The attackers spent six months building trust, compromised contributor devices, manipulated a multisig into pre-signing its own destruction, and drained $285 million in 12 minutes.
The response infrastructure — Circle's CCTP, Solana's monitoring, the broader DeFi security ecosystem — had hours to intervene and did not. The Solana Foundation's STRIDE program, launched five days later, is a code-level defense against a people-level attack.
For DeFi protocols managing significant TVL, the Drift incident establishes a new baseline: timelocks are not optional, multisig signer operational security requires the same rigor as private key management, and reliance on stablecoin issuers to freeze illicit flows in real time is not a viable security assumption.
The $285 million is almost certainly unrecoverable.