Drift Protocol, the largest perpetual futures exchange on Solana by open interest, lost an estimated $285 million on April 1, 2026, in what blockchain analytics firms TRM Labs and Elliptic have attributed with medium confidence to North Korean state-sponsored hackers. The attack — executed in 12 ...
"USDC freezes only occur under legal orders. We cannot and should not become an unilateral judge of onchain disputes." — Dante Disparte, Chief Strategy Officer, Circle Internet Financial
Drift Protocol, the largest perpetual futures exchange on Solana by open interest, lost an estimated $285 million on April 1, 2026, in what blockchain analytics firms TRM Labs and Elliptic have attributed with medium confidence to North Korean state-sponsored hackers. The attack — executed in 12 minutes — followed a six-month social engineering campaign that compromised multisig signers and exploited Solana's durable nonce feature to pre-sign dormant governance transactions.
The incident is the largest DeFi exploit of 2026 to date and the second-largest in Solana's history, behind only the $326 million Wormhole bridge hack of February 2022. As of April 11, no compensation plan has been finalized. A class action investigation has been opened by Gibbs Mura, A Law Group, and Circle Internet Financial faces scrutiny for not freezing stolen USDC despite having the technical capacity to do so.
The Solana Foundation responded on April 7 by launching STRIDE, a structured security evaluation program, and the Solana Incident Response Network (SIRN). Both initiatives are reactive measures following the ecosystem's most significant governance failure.
The exploit on April 1 was the culmination of operational groundwork laid over approximately six months, according to Drift's own post-mortem published April 5.
Fall 2025: Attackers posing as a quantitative trading firm initiated contact with Drift contributors. According to CoinDesk, the social engineering campaign involved a malicious code repository and a fake TestFlight application designed to compromise contributor devices.
March 23, 2026: Four durable nonce accounts were created on Solana. Two were associated with legitimate Drift Security Council members. Two were controlled by the attacker. According to BlockSec's technical analysis, this indicates the attacker had already obtained valid signatures from two of five council members, locked into durable nonce transactions with no expiration.
April 1, 2026 (execution window: ~12 minutes): Approximately one minute after Drift ran a routine test withdrawal, the attacker submitted pre-signed durable nonce transactions. Two transactions, four slots apart on the Solana blockchain, were sufficient to create and approve a malicious admin transfer, then approve and execute it. The attacker executed 31 withdrawals, draining the protocol's vaults.
April 1–2: Over $230 million in stolen assets were swapped to USDC and bridged to Ethereum via Circle's Cross-Chain Transfer Protocol (CCTP).
April 5: Drift published its incident report, attributing the attack to a six-month DPRK intelligence operation.
April 7: Solana Foundation announced STRIDE and SIRN security programs.
April 9: U.S. Treasury expanded cyber intelligence sharing, offering free threat intelligence to crypto firms. Gibbs Mura opened a class action investigation.
The exploit combined two distinct attack vectors: governance compromise via durable nonces and collateral fraud via oracle manipulation.
Solana transactions normally expire after approximately 90 seconds if the referenced blockhash passes. Durable nonces override this safety mechanism by replacing the expiring blockhash with a fixed nonce stored in a special onchain account. A signed transaction using a durable nonce remains valid indefinitely until submitted or until the nonce account is manually advanced.
According to CoinDesk's technical reporting, the attackers exploited this by obtaining legitimate signatures from Security Council members under false pretenses. The signers had no mechanism to revoke approval once given, and most users do not monitor nonce account status. The result: governance transactions pre-signed weeks in advance were submitted on April 1 as if freshly authorized.
A zero-timelock Security Council migration — meaning governance changes took effect immediately with no delay period — eliminated the protocol's last procedural safeguard.
Separately, the attacker manufactured an entirely fictitious asset: CarbonVote Token (CVT). According to TRM Labs' analysis, the attacker minted approximately 750 million CVT units, seeded a small liquidity pool (~$500) on Raydium, and used wash trading over several weeks to build a price history near $1.
Drift's oracle infrastructure picked up the artificial price signal and treated CVT as legitimate collateral. With full admin privileges obtained through the governance compromise, the attacker introduced CVT as an accepted collateral asset, inflated its oracle price, relaxed withdrawal protections, and drained high-value assets through the protocol's lending pathways.
As Chainalysis noted in its post-incident analysis, the critical failure was not a smart contract bug. The vulnerability sat at the intersection of human trust and onchain governance — a gap no standard smart contract audit is designed to cover. The attackers social-engineered multisig signers into pre-signing hidden authorizations, a technique that rendered code-level security irrelevant.
Elliptic flagged the exploit as a likely North Korea-linked operation on April 2, citing laundering patterns and onchain timestamps consistent with Lazarus Group tradecraft. TRM Labs published a separate analysis attributing the attack to a DPRK-affiliated group tracked under multiple designations: UNC4736, AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces.
According to The Hacker News, researchers at CryptoTimes have documented evidence that North Korean IT workers have been infiltrating DeFi development teams for years, sometimes maintaining positions for months before executing attacks. The Drift incident fits this established pattern of long-duration social engineering operations preceding rapid technical exploitation.
DPRK-linked actors have stolen an estimated $1.5 billion from crypto protocols since 2022, according to Chainalysis data. The Drift exploit represents approximately 19% of that cumulative total in a single incident.
The immediate market reaction was severe:
As of April 11, no detailed compensation plan or timeline has been published. Drift stated it is working with Asymmetric Research and OtterSec on a coordinated recovery plan.
The most contentious post-exploit development involved Circle Internet Financial's decision not to freeze stolen USDC.
According to CoinDesk, the attacker bridged over $230 million to Ethereum via Circle's CCTP over a period of several hours following the exploit. Circle made no intervention despite having the technical ability, contractual authority under USDC's terms of service, and operational precedent — the company had aggressively frozen 16 unrelated business wallets in a separate civil matter just nine days earlier.
Circle's Chief Strategy Officer Dante Disparte stated that USDC freezes only occur under legal orders, and called on Congress to accelerate the GENIUS Act and CLARITY Act to establish clearer legal frameworks for intervention.
The asymmetry in Circle's freeze actions — proactive in a civil dispute, passive during a state-sponsored theft — has drawn attention from attorneys. Gibbs Mura is reviewing potential claims against Circle for alleged failure to act. CryptoBriefing reported that Circle has since called for industry-wide "circuit breakers" — automated mechanisms to pause cross-chain transfers when anomalous activity is detected.
The incident exposes an unresolved tension in stablecoin design: centralized issuers hold discretionary freeze authority but lack standardized criteria for when to exercise it.
Five days after the exploit, the Solana Foundation announced two security initiatives:
STRIDE (Structured Threat Response and Institutional DeFi Evaluation): Developed in partnership with Asymmetric Research, STRIDE will evaluate Solana DeFi protocols against eight security pillars. Protocols with more than $10 million in TVL that pass the evaluation will receive ongoing operational security monitoring funded by Foundation grants. Coverage is calibrated to each protocol's risk profile.
SIRN (Solana Incident Response Network): A membership-based group of security firms and researchers focused on real-time crisis response. Founding members include OtterSec, Neodyme, Squads, and ZeroShadow.
Both programs address post-exploit remediation rather than the root cause. As multiple security researchers have noted, the Drift attack exploited the gap between onchain correctness and offchain human trust. No smart contract audit, monitoring tool, or automated evaluation framework is designed to detect a six-month social engineering campaign targeting multisig signers.
The STRIDE program's $10 million TVL threshold also leaves smaller protocols — which collectively hold billions in user funds — outside its coverage.
Class Action Investigation: Gibbs Mura, A Law Group announced on April 7 that it has opened an investigation into the Drift Protocol exploit, urging affected investors to file claims. The investigation covers potential claims against both Drift's governance structure and Circle's inaction.
U.S. Treasury Response: On April 9, the Treasury Department expanded cyber intelligence sharing, offering free threat intelligence feeds to crypto firms. The move was described as a direct response to sophisticated state-sponsored attacks like the Drift exploit.
Legislative Pressure: The incident has added urgency to ongoing Congressional debates. Circle explicitly cited the Drift exploit when calling for faster passage of the GENIUS Act (stablecoin regulation) and CLARITY Act (market structure). Senator Bernie Moreno stated that digital asset legislation must pass by May or face indefinite delay, according to Yahoo Finance.
The Drift Protocol exploit demonstrates that DeFi's most consequential vulnerabilities are no longer in smart contract code. The protocol's contracts functioned as designed. The failure was in governance architecture — specifically, the absence of timelocks on Security Council actions, the irrevocability of durable nonce signatures, and the lack of human verification procedures for multisig operations.
State-sponsored actors are now investing six months of intelligence tradecraft into single protocol exploits. The economic value at risk in DeFi governance — where a small number of human signers control access to hundreds of millions in pooled assets — has made protocols high-value targets for nation-state operations.
The Solana Foundation's STRIDE program and the broader industry push for circuit breakers and legal frameworks represent necessary but insufficient responses. Until governance designs enforce mandatory timelocks, implement signer verification protocols resistant to social engineering, and establish standardized intervention criteria for centralized stablecoin issuers, the gap between code security and human security will remain the sector's primary attack surface.