On April 1, 2026, attackers drained $285 million from Drift Protocol — Solana's largest decentralized perpetual futures exchange — in 12 minutes. The exploit was not a smart contract vulnerability. It was a six-month social engineering campaign that compromised two of five multisig signers, combi...
"The critical vulnerability was not a smart contract bug but a combination of social engineering multisig signers into pre-signing hidden authorizations and a zero-timelock Security Council migration." — Drift Protocol Incident Report, April 2, 2026
On April 1, 2026, attackers drained $285 million from Drift Protocol — Solana's largest decentralized perpetual futures exchange — in 12 minutes. The exploit was not a smart contract vulnerability. It was a six-month social engineering campaign that compromised two of five multisig signers, combined with the abuse of a legitimate Solana transaction feature called durable nonces and the removal of a critical timelock four days before execution.
Blockchain analytics firms TRM Labs and Elliptic attributed the attack with moderate-to-high confidence to UNC4736 (also tracked as AppleJeus or Citrine Sleet), a North Korean state-affiliated threat actor previously linked to the October 2024 Radiant Capital attack. According to TRM, this was the 18th DPRK-linked crypto theft of 2026, with total attributed losses exceeding $300 million in Q1 alone.
Drift's total value locked fell from $550 million to under $300 million within an hour. The DRIFT token dropped 42%. Twelve Solana protocols with exposure to Drift liquidity paused operations. Circle faced public criticism for failing to freeze stolen USDC during the six-hour window before the attacker bridged funds to Ethereum.
The Drift exploit combined three distinct attack vectors into a single coordinated operation:
No private keys were stolen. No smart contract code was exploited. The attacker obtained two legitimate signatures from Drift's 2-of-5 Security Council multisig through misrepresentation, then held those signatures dormant for over a week using Solana's durable nonce mechanism before executing them in a coordinated 12-minute drain.
Between December 2025 and January 2026, the threat actor integrated into an ecosystem vault within Drift. According to Drift's incident report, the group submitted detailed strategic forms, engaged with contributors through extensive work sessions, and invested more than $1 million of their own capital — a tactic designed to establish financial credibility.
Drift participants met members of the group face-to-face at multiple industry events over nearly six months. Throughout the engagement, the attackers shared files, links, and project resources with the team. They asked detailed technical questions that demonstrated genuine protocol knowledge. According to the SEALS 911 investigation team, this pattern mirrors the Radiant Capital attack of October 2024, where DPRK operatives maintained a similar months-long presence before striking.
The social engineering was not opportunistic. It was a resourced, patient intelligence operation with a specific target and predetermined extraction timeline.
Solana's durable nonce feature is designed for legitimate use cases: offline signing, complex multisig workflows, and scenarios where transactions need to remain valid beyond the network's standard expiration window. A normal Solana transaction expires within roughly 90 seconds. A durable nonce transaction has no expiration.
Between March 23 and March 30, the attacker created four durable nonce accounts — two linked to Drift Security Council multisig members, and two controlled by the attacker. According to CoinDesk's technical analysis, this indicated that at least two of five signers had already signed transactions tied to these nonce accounts, giving the attacker the required 2-of-5 approval threshold.
Drift describes these as "unauthorized or misrepresented transaction approvals," indicating the signers believed they were approving routine operations.
The decisive failure occurred on March 27. Drift migrated its Security Council to a new 2-of-5 threshold configuration with zero timelock. Timelocks typically impose a 24-to-72-hour delay on administrative actions, providing a window for community detection and intervention. Removing this safeguard converted a complex multi-week attack into a 12-minute cash-out. According to BlockSec's post-incident analysis, the timelock removal was the single point of failure that made the full drain possible.
Weeks before the execution, the attacker deployed a fabricated token called CarbonVote Token (CVT), minting approximately 750 million units. They seeded a liquidity pool on Raydium with roughly $500 and used continuous wash trading to build a credible price history near $1 per token.
According to TRM Labs, the initial funding — 10 ETH withdrawn from Tornado Cash on March 11 — began moving at approximately 12:00 AM GMT on March 12, which corresponds to 09:00 Pyongyang time. The ETH funded the CVT deployment shortly after.
Over several weeks, the wash-traded price history was picked up by Drift's oracle feeds, which treated CVT as legitimate collateral worth hundreds of millions of dollars. On execution day, the attacker listed CVT as valid collateral on Drift using the compromised governance authority, raised withdrawal limits to extreme levels, and deposited hundreds of millions of CVT tokens against which Drift's risk engine issued real assets.
The oracle manipulation was not a flash loan attack or a single-block price spike. It was a slow, methodical poisoning of price feeds over weeks — a far more sophisticated approach than the typical DeFi exploit.
On April 1, the attacker activated the pre-signed durable nonce transactions. The sequence: list CVT as collateral, raise withdrawal limits, deposit CVT, and execute 31 withdrawal transactions draining real assets — USDC, JLP, SOL, WBTC, and other tokens — in approximately 12 minutes.
According to Drift's incident report, most stolen funds were bridged to Ethereum within hours using Circle's Cross-Chain Transfer Protocol (CCTP). On Ethereum, portions were converted to ETH while some moved through centralized exchanges.
Blockchain investigator ZachXBT highlighted that Circle had approximately six hours to freeze the stolen USDC as it moved through Circle's infrastructure. He contrasted this inaction with Circle's recent decision to freeze 16 unrelated corporate hot wallets in a sealed U.S. civil case — actions ZachXBT characterized as overreach.
According to Crowdfund Insider, Circle faced criticism for what observers described as a compliance gap. The stolen USDC moved unimpeded through CCTP while Circle had both the technical ability and legal precedent to intervene. As of April 5, no comprehensive reimbursement plan had been announced by either Drift or Circle.
The incident has reignited debate about centralized issuers' responsibilities during exploits. USDC's freezing capability is a known feature — Circle has frozen funds in prior incidents — making the inaction during a confirmed DPRK-linked theft a subject of industry scrutiny.
The immediate damage was concentrated but significant:
According to reporting from Tekedia, some affected protocols reported limited exposure and moved to reimburse users, while others temporarily halted deposits, withdrawals, or borrowing functions. The damage was deep within Drift's orbit but did not cascade into a broader Solana DeFi crisis.
The Drift exploit fits into a broader pattern. According to TRM Labs:
According to 38 North's January 2026 analysis, North Korea has transitioned from "digital kleptocracy" to what researchers describe as a "rogue crypto-superpower." The Drift exploit demonstrates a continued evolution in sophistication: from code exploits to long-duration social engineering operations that target governance structures rather than smart contracts.
OFAC has expanded sanctions targeting DPRK IT workers infiltrating Web3 companies. The Drift case — where attackers attended industry events in person and maintained a six-month cover — represents the next escalation in this threat model.
The Drift exploit exposed three systemic vulnerabilities that extend beyond a single protocol:
1. Multisig governance is a social attack surface. A 2-of-5 threshold with no timelock means two compromised or deceived signers can execute arbitrary protocol changes instantly. According to BlockSec, the combination of low threshold, zero timelock, and durable nonces created a governance structure that was technically functional but operationally indefensible.
2. Oracle poisoning through manufactured tokens is underpriced as a risk. Drift's oracles accepted a token with $500 in initial liquidity and weeks of wash trading as collateral worth hundreds of millions. The oracle infrastructure did not flag the disconnect between trading volume, liquidity depth, and stated valuation.
3. Durable nonces are a double-edged feature. Separating signature time from execution time creates an inherent security gap. CoinDesk's analysis noted that this legitimate convenience feature enabled the attacker to pre-stage an administrative takeover that appeared as normal multisig activity until the moment of execution.
For protocols managing significant TVL, the Drift case argues for higher multisig thresholds (3-of-5 or 4-of-7), mandatory timelocks on all administrative actions, and oracle systems that weight liquidity depth and trading history duration against stated token valuations.
The Drift exploit is not a story about broken code. It is a story about broken assumptions — that multisig governance with low thresholds provides adequate security, that oracles can distinguish manufactured price feeds from organic ones, and that social engineering at this scale is unlikely against sophisticated DeFi teams.
The $285 million loss ranks as the largest DeFi exploit of 2026. It demonstrates that as smart contract auditing has matured, state-sponsored threat actors have shifted to softer targets: governance structures, human relationships, and the seams between legitimate features and their unintended applications. The durable nonce mechanism worked exactly as designed. The attacker simply found a use case its designers did not anticipate.
For the DeFi sector, the lesson is structural. Security is not a property of code alone. It is a property of the entire system — including the humans who sign transactions and the governance frameworks that constrain what those signatures can do.