← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] DPRK Agents Drained Drift's $285M in 12 Minutes

Zephyra|April 9, 2026|BPF
EXECUTIVE SUMMARY

On April 1, 2026, attackers drained $285 million from Drift Protocol — Solana's largest perpetual futures DEX — in 12 minutes. The exploit was not a smart contract vulnerability. It was the culmination of a six-month social engineering campaign attributed with medium-high confidence to UNC4736, a...

"Circle was asleep while many millions of USDC were swapped via CCTP from Solana to Ethereum for hours from the 9-figure Drift hack during US hours." — ZachXBT, Blockchain Investigator

Executive Summary

On April 1, 2026, attackers drained $285 million from Drift Protocol — Solana's largest perpetual futures DEX — in 12 minutes. The exploit was not a smart contract vulnerability. It was the culmination of a six-month social engineering campaign attributed with medium-high confidence to UNC4736, a North Korean state-affiliated hacking group also tracked as AppleJeus and Citrine Sleet.

The attackers manufactured a fictitious token, manipulated oracles into treating it as legitimate collateral, and used a legitimate Solana feature — durable nonce accounts — to pre-sign administrative transactions weeks before execution. DRIFT token fell 42% to an all-time low of $0.033. Protocol TVL collapsed from $550 million to $232 million. SOL dropped 5.5% within hours.

The fallout extends well beyond Drift. Circle faces a class-action investigation for failing to freeze $232 million in stolen USDC that traversed its own bridge infrastructure over six hours during U.S. business hours. The Solana Foundation launched the STRIDE security program on April 6. Drift floated an IOU airdrop compensation plan that drew immediate backlash. The incident exposes structural governance failures in DeFi that no amount of code auditing can address.

Table of Contents

  1. The Attack: Anatomy of a 12-Minute Drain
  2. The Setup: Six Months of Social Engineering
  3. The CarbonVote Token: Manufacturing Fake Collateral
  4. Circle's Inaction: $232M Crossed Its Own Bridge
  5. Market Impact and Token Fallout
  6. Solana Foundation Response: STRIDE and SIRN
  7. Legal Exposure: Class-Action Investigation Opens
  8. The IOU Airdrop Proposal and Its Problems
  9. DPRK's Expanding Crypto Theft Operation
  10. Key Takeaways
  11. Conclusion

The Attack: Anatomy of a 12-Minute Drain

At approximately 12:00 UTC on April 1, 2026, attackers executed 31 rapid withdrawals from Drift Protocol's vaults, draining approximately $285 million in USDC, JLP, SOL, and other tokens. The entire extraction took roughly 12 minutes, according to TRM Labs.

The critical vulnerability was a compromised multisig governance structure. On March 27, Drift had migrated its Security Council to a new 2-of-5 threshold configuration with zero timelock — eliminating the mandatory delay that would have allowed detection and intervention before administrative actions took effect. The attacker had already obtained the required two-of-five approval threshold through social engineering.

Stolen assets were consolidated and swapped into USDC and SOL. According to Elliptic, the majority was bridged from Solana to Ethereum using Circle's Cross-Chain Transfer Protocol (CCTP) in more than 100 separate transactions over approximately six hours. On Ethereum, portions were converted into ETH, while some funds moved through centralized exchanges.

This is the largest DeFi exploit of 2026 and the second-largest security incident in Solana's history, behind only the $326 million Wormhole bridge hack in February 2022.

The Setup: Six Months of Social Engineering

According to Drift's post-incident report published April 6, the operation began in the fall of 2025. Operatives posing as a quantitative trading firm initiated contact with Drift contributors. Over six months, the attackers built working relationships with multiple team members, meeting face-to-face at several major industry conferences across different countries in February and March 2026, according to reporting by The Hacker News and Gizmodo.

The attack is attributed with medium-high confidence to UNC4736, also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces. This is the same group linked to the $50 million Radiant Capital hack in October 2024, as identified by Mandiant.

The attackers compromised contributor devices through a malicious code repository and a fake TestFlight application. With device access, they induced multisig signers into pre-signing transactions that appeared routine but carried hidden authorizations for critical admin actions, according to CoinDesk.

Between March 23 and March 30, the attacker created multiple durable nonce accounts — a legitimate Solana feature that allows transactions to be pre-signed and executed later without expiring. According to BlockSec's analysis, four durable nonce accounts were created: two associated with Drift Security Council multisig members and two associated with attacker-controlled accounts. On March 30, a new durable nonce account appeared tied to a member of the updated multisig, confirming the attacker had re-obtained the required signing threshold under the new 2-of-5 configuration.

The CarbonVote Token: Manufacturing Fake Collateral

The attacker created a fictitious token called CarbonVote Token (CVT), minting approximately 750 million units, according to TRM Labs. The attacker controlled more than 80% of the supply. On-chain staging began on March 11 with a 10 ETH withdrawal from Tornado Cash.

The attacker seeded a liquidity pool on Raydium with approximately $500 and used wash trading — buying and selling between their own wallets — to build a fake price history near $1 per token. Drift's oracles treated CVT as legitimate collateral worth hundreds of millions of dollars.

Using the inflated CVT position as collateral, the attacker executed the 31 rapid withdrawals, draining real assets — USDC, JLP, SOL, and other tokens — from Drift's vaults.

Circle's Inaction: $232M Crossed Its Own Bridge

The most contentious aspect of the aftermath centers on Circle Internet Financial. According to blockchain investigator ZachXBT, approximately $232 million in stolen USDC was bridged from Solana to Ethereum via Circle's CCTP over six hours during U.S. business hours. Circle took no action to freeze the funds.

The backlash intensified because of a contrasting precedent. According to ZachXBT, nine days before the Drift hack, Circle had frozen 16 business wallets in a separate civil matter — including DFINITY Foundation's ckETH Minter contract — demonstrating both the capability and willingness to freeze assets. Five of those wallets were later unfrozen.

Circle has stated it freezes assets when legally required, citing potential legal liability from unauthorized freezes. According to ZachXBT's broader investigation published after the incident, he identified 15 cases totaling more than $420 million in illicit USDC flows that Circle failed to freeze promptly since 2022.

Market Impact and Token Fallout

The immediate market impact was severe:

  • DRIFT token: Fell 42% to an all-time low of $0.033 within 24 hours of the exploit, according to CoinMarketCap data.
  • Drift Protocol TVL: Collapsed from approximately $550 million to $232 million — a 58% decline in a single morning, according to DefiLlama.
  • SOL: Dropped 5.5% immediately following the exploit. As of April 4, SOL traded near $80 on Binance, with perpetual futures funding rates at -0.0042%, according to Ainvest.
  • Team token movements: On April 4, Onchain Lens reported a wallet linked to the Drift team deposited 56.25 million DRIFT tokens (valued at $2.44 million) into Bybit and Gate exchanges, drawing scrutiny from the community during the ongoing liquidity crisis.

Solana Foundation Response: STRIDE and SIRN

On April 6, the Solana Foundation and Asymmetric Research launched STRIDE (Solana Trust, Resilience and Infrastructure for DeFi Enterprises), a tiered DeFi security program, according to CoinDesk.

The program's structure, as reported:

  • Protocols with >$10M TVL: Ongoing operational security and active threat monitoring funded by Solana Foundation grants.
  • Protocols with >$100M TVL: Additional formal verification — mathematical checking of every possible execution path.

The Foundation also launched the Solana Incident Response Network (SIRN), a coalition including Asymmetric Research, OtterSec, Neodyme, Squads, and Zeroshadow for real-time crisis response.

A critical limitation, acknowledged by multiple security researchers: STRIDE's formal verification and on-chain monitoring would not have caught this attack. The transactions were valid by design — legitimate administrative actions executed via properly authorized multisig signers — and indistinguishable from routine operations until the vaults were emptied.

Legal Exposure: Class-Action Investigation Opens

On April 7, Gibbs Mura, A Law Group announced a class-action investigation on behalf of Drift investors, according to Business Wire. The investigation focuses not on the hackers but on potential claims against Circle Internet Financial for its alleged failure to act despite having the technical ability, contractual authority, and operational precedent to freeze the stolen USDC.

Separately, a legal expert quoted by The Coin Republic on April 7 characterized the incident as a potential civil negligence case against Drift's operators, citing the zero-timelock Security Council migration as a governance failure that removed a critical safeguard.

The IOU Airdrop Proposal and Its Problems

Solana co-founder Anatoly Yakovenko publicly suggested that Drift could survive by issuing IOU tokens — an "airdrop" to affected users with the core engineering team rebuilding the platform and using the tokens to eventually make users whole. The model mirrors Bitfinex's approach after its $72 million hack in 2016, as reported by Yahoo Finance.

The proposal faced immediate criticism. Analysts argued that describing the issuance as an "airdrop" obscures the core issue: without a solvent protocol and a viable path to repayment, the tokens carry no intrinsic value beyond speculation on future recovery, according to BeInCrypto.

The Drift team's deposit of 56.25 million DRIFT tokens to centralized exchanges during the crisis compounded skepticism about the viability of any internal compensation plan.

DPRK's Expanding Crypto Theft Operation

The Drift exploit fits within a pattern of accelerating North Korean crypto theft. According to data compiled by Chainalysis and Elliptic:

  • 2024: DPRK-linked actors stole $1.3 billion across 47 incidents.
  • 2025: $2.02 billion stolen — a 51% increase year-over-year, representing nearly 60% of all global crypto theft. The single largest incident was the $1.5 billion Bybit hack in February 2025.
  • Q1 2026: $309 million stolen across 12 incidents, with the Drift exploit accounting for $285 million — 92% of the quarter's total.
  • Cumulative all-time: More than $6.75 billion in cryptocurrency stolen since 2017, according to BlockEden.xyz analysis of multiple tracking sources.

The Drift attack shares the same operational signature as the October 2024 Radiant Capital hack: extended social engineering, compromised devices, multisig manipulation, and rapid fund extraction.

Key Takeaways

  • The $285 million Drift exploit was not a code vulnerability. It was a six-month social engineering operation that compromised governance — the human layer that code audits do not cover.
  • Drift's zero-timelock Security Council migration on March 27 removed the last technical safeguard that could have prevented execution. Governance design is a security function, not an administrative convenience.
  • Circle's failure to freeze $232 million in stolen USDC traversing its own bridge over six hours raises fundamental questions about stablecoin issuer responsibility during active exploits.
  • The Solana Foundation's STRIDE program addresses code-level vulnerabilities but acknowledges it would not have prevented this attack. No existing framework systematically addresses multisig social engineering at scale.
  • DPRK-linked actors have stolen $309 million in Q1 2026 alone, with cumulative all-time theft exceeding $6.75 billion. The operational sophistication — six months of in-person relationship building — represents an escalation in attack methodology.
  • The class-action investigation against Circle, rather than the hackers, signals a potential shift in DeFi liability frameworks toward infrastructure providers.

Conclusion

The Drift Protocol exploit demonstrates that the primary attack surface in DeFi has shifted from smart contract code to governance and human operations. Drift's contracts passed audits. Its code was sound. The attackers spent six months building trust, compromised contributor devices, manipulated a multisig into pre-signing its own destruction, and drained $285 million in 12 minutes.

The response infrastructure — Circle's CCTP, Solana's monitoring, the broader DeFi security ecosystem — had hours to intervene and did not. The Solana Foundation's STRIDE program, launched five days later, is a code-level defense against a people-level attack.

For DeFi protocols managing significant TVL, the Drift incident establishes a new baseline: timelocks are not optional, multisig signer operational security requires the same rigor as private key management, and reliance on stablecoin issuers to freeze illicit flows in real time is not a viable security assumption.

The $285 million is almost certainly unrecoverable.

Sources & References

  1. TRM Labs: North Korean Hackers Attack Drift Protocol In USD 285 Million Heist — TRM Labs incident analysis and DPRK attribution
  2. Elliptic: Drift Protocol exploited for $286 million in suspected DPRK-linked attack — Elliptic blockchain analysis and fund tracing
  3. The Hacker News: $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation — Timeline of the social engineering campaign
  4. CoinDesk: How a Solana feature designed for convenience let an attacker drain $270 million from Drift — Durable nonce account mechanics
  5. CoinDesk: Circle under fire after $285 million Drift hack over inaction to freeze stolen USDC — Circle controversy and ZachXBT investigation
  6. BlockSec: Drift Protocol Incident — Multisig Governance Compromise via Durable Nonce Exploitation — Technical breakdown of the exploit mechanism
  7. CoinDesk: Solana Foundation launches security overhaul days after $270 million Drift exploit — STRIDE program and SIRN details
  8. Business Wire: Drift Protocol Cryptocurrency Hack Class Action Lawsuit Investigation — Gibbs Mura class-action investigation announcement
  9. Yahoo Finance: Solana's Drift Floats Airdrop After $285 Million Hack, Faces Backlash — IOU token proposal and community response
  10. The Block: Blockchain sleuth ZachXBT accuses Circle of slow USDC freezes across more than $420 million in illicit funds — ZachXBT's broader investigation into Circle freeze patterns
  11. CCN: Drift Protocol Hit by $285M Exploit — Attack execution details and timeline
  12. Gizmodo: Crypto Project Details Alleged 6-Month North Korean Intel Op Behind $285 Million Hack — Long-form account of the infiltration