On April 1, 2026, Solana-based DeFi protocol Drift Protocol suffered a catastrophic hack, losing between $280 million and $285 million in user funds. The legal fallout is now targeting stablecoin issuer Circle, as U.S. law firm Gibbs Mura files a class action investigation against the company over its failure to freeze stolen assets.
North Korean Hackers Seize Governance, $280M Gone Overnight
Blockchain analytics firm Elliptic suspects the attack was orchestrated by North Korean state-backed hackers. The attackers exploited Solana's legitimate functions, pre-signing governance transactions weeks in advance and executing them at a critical moment to take control of Drift. The impact was severe: Drift's TVL plunged from $550 million to under $250 million, its native token DRIFT dropped over 40%, and at least 20 other DeFi protocols suffered indirect losses due to exposure.
Circle Accused of Double Standard: Freezes Corporate Wallets but Spares Hackers
Gibbs Mura revealed in its announcement that after the hack, the attackers spent over six hours executing more than 100 transactions, using Circle's Cross-Chain Transfer Protocol (CCTP) to move over $230 million in stolen USDC from Solana to Ethereum. Circle took no action to freeze these funds. The law firm noted that just nine days before the Drift incident, Circle had quickly frozen 16 corporate wallets in a separate civil case, proving its technical capability and willingness to act. Gibbs Mura condemned Circle's "double standard" in exercising freeze powers—acting decisively against legitimate businesses while ignoring a confirmed nine-figure hack.
Class Action Scrutinizes Circle's Infrastructure and Duty of Care
The class action investigation will focus on: whether Circle failed to freeze stolen USDC despite having the technical and contractual ability; whether it failed to adequately monitor its CCTP infrastructure; and whether, as a regulated stablecoin issuer, it violated duties owed to users trusting USDC. Gibbs Mura is operating on a contingency fee basis, requiring no upfront costs from victims. This lawsuit could redefine the legal and regulatory responsibilities of centralized stablecoin issuers in DeFi hacking incidents.

