Drift Trade
- Technique
- Proxy Upgrade Hijack
- Classification
- Access Control
- Target type
- DeFi Protocol
- Affected chains
- Solana
- Source
- No public source link
On April 1, 2026, Solana perpetuals protocol Drift lost $295 million — more than half its TVL — in an extraction phase lasting a few hours, preceded by six months of preparation. The cause wasn't a smart-contract bug but a compromised protocol admin multisig. It ranks as the largest DeFi exploit of 2026 and Solana's second-largest breach on record. Analysts at Chainalysis note indicators consistent with previously attributed North Korea-linked operations; full formal attribution wasn't confirmed across every report at the time of writing.
How the attack worked
Different write-ups label the mechanism differently — a "privileged-control failure" (Cube Exchange), "oracle manipulation via fake collateral," a "durable-nonce exploit" — but at its core it combines two elements: a compromised admin key and a token with a fabricated price accepted as legitimate collateral. Behind that label sits a six-month operation:
- Social engineering (fall 2025 – March 2026). Attackers posed as a quant trading firm, spent months building relationships with Drift contributors at conferences and over Telegram, and deposited over $1 million to establish credibility.
- Fake collateral. On March 12 they created a token called CarbonVote (CVT), controlling roughly 80% of its supply. A Raydium pool seeded with about $500 in real liquidity was used to wash-trade CVT between their own wallets, manufacturing a price history near $1.
- Durable-nonce exploitation. Between March 23–30, attackers collected pre-signed transactions from Security Council members via Solana's durable-nonce feature, which lets a transaction be signed in advance and executed offline at any later time. A March 26 migration to a 2-of-5 multisig with no timelock removed the window in which such a transfer could have been caught.
- Extraction (April 1, 16:05–18:31 UTC). The pre-signed transactions were submitted together, handing admin control to the attacker, who whitelisted CVT as collateral with no borrow limit, deposited hundreds of millions of CVT at the fabricated price, and withdrew real assets across 18+ tokens — including $71.4M in USDC, $159.3M in JLP, and $11.3M in cbBTC.
Roughly $230 million of the stolen funds moved to Ethereum via Circle's Cross-Chain Transfer Protocol within about 23 minutes, during US business hours, without the USDC issuer intervening — the basis for a separate lawsuit against Circle (NewsBTC).
What happened next
Only about $3.36 million in USDC was frozen; roughly 130,259 ETH (~$31M) sits traceable in attacker-controlled wallets but remains unreturned — recovery from DPRK-linked incidents is historically rare. Instead of recovering the stolen funds, Drift set up a compensation scheme: a recovery token redeemable at $1 per verified dollar of loss, backed by a separately funded $151.3 million pool — up to $127.5 million in Tether credit, partner commitments, and remaining protocol assets (CoinCentral). That's new capital, not funds clawed back from the attacker. A 10% bounty on any assets traced was also offered to outside researchers.
On July 1, 2026, the protocol relaunched under a new name, Velocity, switching settlement from USDC to USDT under a Tether partnership, with a rebuilt security team and hardware-signed transaction requirements (Cryptopolitan).
What this means
- The weak point wasn't contract code but the privileged roles surrounding it: any protocol whose admin multisig can list assets or lift limits without a timelock carries systemic risk regardless of audit quality.
- Durable nonces — signatures given in advance and executable offline at any point — are a Solana-specific mechanic worth weighing when assessing risk on that chain: a transaction signed a month earlier can execute without warning.
- The one signal visible to users ahead of time is a protocol's multisig composition and rules — signer threshold, whether a timelock guards privileged functions — worth checking before depositing meaningful size.
- Since the incident, the industry has discussed moving from signature-validity checks alone to intent-based transaction screening, aimed precisely at attacks where the signature is technically valid but the action isn't.
Sources
- The Drift Protocol Hack: How Privileged Access Led to a $285M Loss — Chainalysis ↗
- The Drift Hack Turned a Compromised Admin Multisig Into a $270 Million Vault Drain — Cube Exchange ↗
- Circle (CRCL) Sued Over $280M Drift Protocol Hack—What Plaintiffs Claim — NewsBTC ↗
- Drift Protocol Got Hacked for $295M — Here's How It Plans to Pay Users Back — CoinCentral ↗
- Drift Protocol relaunches as Velocity DEX with Tether credit line — Cryptopolitan ↗
Sources checked 07.08.2026
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.