On April 1, 2026, Drift Protocol — the largest decentralized perpetual futures exchange on Solana by total value locked — lost approximately $285 million in user assets in under 12 minutes. The attack, attributed with medium confidence to the DPRK-linked threat actor UNC4736 (also tracked as Appl...
"The critical vulnerability was not a smart contract bug but a combination of social engineering multisig signers into pre-signing hidden authorizations and a zero-timelock Security Council migration that eliminated the protocol's last line of defense." — TRM Labs, Post-Incident Analysis
On April 1, 2026, Drift Protocol — the largest decentralized perpetual futures exchange on Solana by total value locked — lost approximately $285 million in user assets in under 12 minutes. The attack, attributed with medium confidence to the DPRK-linked threat actor UNC4736 (also tracked as AppleJeus, Citrine Sleet, and Gleaming Pisces), did not exploit a smart contract bug. It was an operational and social engineering failure: a six-month infiltration campaign culminating in a governance takeover executed through Solana's durable nonce feature and a fabricated collateral token.
The exploit ranks as the largest DeFi hack of 2026 and the second-largest in Solana's history, behind the $326 million Wormhole bridge hack of February 2022. Drift's TVL collapsed 55% from $550 million to under $250 million within an hour. The DRIFT token fell 42% on the day. Contagion spread to more than 20 downstream protocols. As of April 7, 2026, no formal reimbursement plan has been announced, and the bulk of stolen funds have been laundered through Tornado Cash.
The execution took 12 minutes. The preparation took six months.
| Date | Event | |---|---| | Oct 2025 | Attackers begin infiltration under the guise of a quantitative trading firm. In-person meetings with Drift contributors at multiple conferences. | | Feb 2026 | Attackers deposit over $1 million into Drift and integrate an Ecosystem Vault. | | Mar 11 | On-chain staging begins with a 10 ETH withdrawal from Tornado Cash. | | Mar 11–23 | Attacker mints 750 million CarbonVote Token (CVT) units, seeds Raydium liquidity, begins wash trading to fabricate price history. | | Mar 23–30 | Attacker creates multiple durable nonce accounts and socially engineers two Security Council multisig signers into pre-signing transactions. | | Mar 27 | Drift migrates Security Council to a new 2-of-5 threshold configuration with zero timelock, eliminating the delay mechanism that would have allowed detection. | | Apr 1, 16:06:09 UTC | First withdrawal: 41.72 million JLP tokens extracted. | | Apr 1, 16:06:19 UTC | Last primary withdrawal: 2,200 wETH extracted. Total elapsed time: 10 seconds for core drain. | | Apr 1, next 6 hrs | Attacker bridges $232 million USDC from Solana to Ethereum via Circle's CCTP. |
According to PIF Research Labs, the primary vault drainage occurred in a 10-second window between 16:06:09 and 16:06:19 UTC.
The Drift exploit combined three distinct attack vectors, none of which involved a code vulnerability in Drift's smart contracts.
Vector 1: Social Engineering of Multisig Signers. The attackers spent six months building trust. Operating under the cover of a quantitative trading firm, DPRK-linked operatives met Drift Protocol contributors in person at industry conferences across multiple countries, according to a post-incident report published by Drift on April 5. They deposited more than $1 million in the protocol and launched an Ecosystem Vault — establishing the operational legitimacy needed to gain proximity to Security Council members.
Between March 23 and March 30, the attackers induced two of the five Security Council multisig signers to pre-sign transactions. The transactions were presented as routine administrative actions but contained hidden authorizations for critical admin functions, including collateral listing authority and withdrawal limit changes.
Vector 2: Governance Takeover via Durable Nonces. The pre-signed transactions were stored using Solana's durable nonce feature, which allows transactions to remain valid indefinitely until executed — unlike standard Solana transactions that expire within approximately 90 seconds. The signers had no mechanism to revoke their approvals once given.
On March 27, Drift completed a migration of its Security Council to a new 2-of-5 threshold configuration. Critically, the new configuration set the timelock to zero — eliminating the 24-to-72-hour delay that would normally allow community review of administrative actions. The pre-signed transactions became instantly executable the moment the timelock was removed.
Vector 3: Oracle Manipulation via Fabricated Collateral. The attacker manufactured a fictitious token — CarbonVote Token (CVT) — by minting 750 million units, seeding a few thousand dollars in liquidity on Raydium, and conducting wash trades to create a price history near $1.00. When the attacker activated the pre-signed transactions and listed CVT as valid collateral, Drift's oracle infrastructure treated the fabricated token as legitimate. The attacker deposited hundreds of millions of CVT as collateral, against which Drift's risk engine issued real assets — JLP tokens, USDC, wETH, and other holdings.
The exploit has focused attention on Solana's durable nonce feature — a legitimate convenience tool designed to allow offline transaction signing and scheduling. Unlike standard Solana transactions, which must reference a recent blockhash and expire in roughly 90 seconds, durable nonce transactions reference a stored nonce value and remain valid until that nonce is manually advanced.
According to BlockSec's post-incident analysis, the architectural issue is fundamental: durable nonce transactions create indefinitely valid signed authorizations. Once a signer approves a transaction using a durable nonce, there is no native revocation mechanism. The signer must manually advance the nonce account to invalidate the transaction — a step most users do not monitor or understand.
For governance and multisig applications, this creates an asymmetric risk: an attacker who obtains valid signatures can hold them dormant for days or weeks before execution, decoupling the moment of social engineering from the moment of exploitation.
Security researchers at BlockSec have recommended that DeFi protocols disable durable nonces entirely for governance or admin-upgrade transaction paths, or implement mandatory on-chain review stages for any durable nonce transaction targeting administrative functions.
The CarbonVote Token (CVT) component of the attack exposes weaknesses in DeFi oracle and collateral-listing infrastructure.
The attacker spent approximately three weeks — from March 11 to April 1 — constructing a synthetic price history for a worthless token. The steps were methodical: mint 750 million tokens, seed a Raydium liquidity pool with a few thousand dollars in SOL, and conduct wash trades between controlled wallets to generate a stable price chart near $1.00.
When the governance takeover was executed and CVT was listed as valid collateral on Drift, the protocol's oracle feeds — which derived price data from on-chain liquidity pools — reported CVT at face value. The attacker deposited CVT tokens as collateral and withdrew real assets against that collateral.
The listing of a fabricated token as valid collateral was not triggered by a smart contract exploit. It was authorized through the administrative functions unlocked by the pre-signed multisig transactions — a governance decision, not a code bug.
According to Elliptic and TRM Labs, the stolen funds were moved rapidly post-exploit:
As of April 7, no significant portion of the stolen funds has been recovered. Circle did not freeze any of the USDC in transit during the six-hour bridging window, a failure that has triggered a separate lawsuit investigation by Class Law Group against Circle Internet Financial.
Blockchain analytics firms Elliptic and TRM Labs have attributed the attack to North Korean state-sponsored actors with medium confidence, based on multiple indicators:
Drift Protocol described the incident as "an attack six months in the making," assigning attribution to UNC4736, which is also tracked under designations including AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces.
The Lazarus Group — the umbrella designation for DPRK-linked cyber operations — has stolen an estimated $6 billion in cryptocurrency since 2017, according to Elliptic's cumulative tracking data. If attribution is confirmed, the Drift exploit would rank among the group's five largest single operations.
The Drift exploit's effects extended well beyond the protocol itself. SOL dropped 5.5% in the immediate aftermath and extended losses to approximately 13% over the following week, according to CoinGecko data.
More than 20 downstream protocols reported direct or indirect exposure:
| Protocol | Impact | |---|---| | Prime Numbers Fi | Reported losses in the millions (exact figure undisclosed). | | Carrot Protocol | Paused mint and redeem functions after 50% of TVL was affected. | | Pyra Protocol | Disabled withdrawals entirely, leaving user funds inaccessible. | | Piggybank | Lost $106,000; reimbursed users from team treasury. |
The DRIFT token fell from approximately $0.074 pre-hack to $0.043 by April 3 — a 42% decline. As of April 7, it trades at approximately $0.043, down 98% from its November 2024 all-time high of $2.65.
Solana DeFi TVL contracted approximately $800 million in the 48 hours following the exploit, according to DefiLlama data, though part of this decline is attributable to the broader market sell-off driven by tariff-related risk-off sentiment.
The role of Circle Internet Financial in the Drift aftermath has drawn sustained scrutiny, though this topic is covered in greater detail in a separate report.
The key facts: $232 million in stolen USDC transited Circle's proprietary CCTP bridge over a six-hour period during U.S. business hours with no freeze action. On-chain investigator ZachXBT noted that Circle had demonstrated its freeze capability nine days earlier when it blacklisted 16 business wallets — including DFINITY Foundation's ckETH Minter contract — in a sealed civil case. At least five of those wallets were subsequently unfrozen.
Circle's stated position is that it freezes assets "when legally required." Class Law Group has initiated an investigation into potential civil claims against Circle for its failure to act during the Drift exploit.
The Drift exploit has prompted a reassessment of DeFi governance security across the industry. Several structural weaknesses have been identified:
1. Multisig threshold and timelock standards. Drift operated a 2-of-5 multisig with zero timelock at the time of the exploit. Security researchers at BlockSec recommend a minimum 3-of-5 or 4-of-7 threshold with mandatory 24–48 hour timelocks for all administrative actions.
2. Durable nonce restrictions. The Solana Foundation has not issued a formal response regarding durable nonce governance risks. Security firms recommend protocols disable durable nonces entirely for governance transactions or implement mandatory on-chain review stages.
3. Oracle and collateral-listing controls. The ability to list a fabricated token as valid collateral through administrative functions — without independent oracle validation — represents a single point of failure. Protocols with administrative collateral-listing authority require independent verification layers and minimum liquidity thresholds enforced at the oracle level.
4. Social engineering resilience. The Drift exploit joins the Ronin Bridge ($625 million), Harmony Horizon ($100 million), and Radiant Capital ($50 million) in a growing category of DeFi exploits driven primarily by social engineering rather than code vulnerabilities. DPRK-linked actors have demonstrated persistent, multi-month infiltration capabilities that exceed the operational security awareness of most DeFi teams.
The Drift Protocol exploit demonstrates that DeFi's primary attack surface has shifted from smart contract vulnerabilities to operational and governance failures. Code audits — while necessary — would not have prevented this attack. The exploit chain was entirely operational: social engineering of human signers, exploitation of a convenience feature (durable nonces), removal of a timelock governance safeguard, and manufacturing of fake collateral to satisfy an oracle system that lacked independent validation.
The DPRK attribution, if confirmed, places the Drift hack within a pattern of increasingly sophisticated state-sponsored attacks on DeFi infrastructure. The Lazarus Group's operational playbook — multi-month infiltration, conference attendance, trust-building through protocol participation, and rapid post-exploit laundering — has proven effective across multiple nine-figure exploits.
For the Solana ecosystem and DeFi broadly, the implications are structural. Multisig governance models require minimum threshold standards and mandatory timelocks. Durable nonces require restrictions for administrative transaction paths. Collateral-listing authority requires independent verification. And operational security against nation-state social engineering campaigns requires capabilities that most DeFi teams do not currently possess.
The $285 million is likely unrecoverable. The lessons are not.