Drift Protocol Hack Drains $286 Million in 12 Minutes, DPRK-Linked Actors Suspected

Drift Protocol Hack Drains $286 Million in 12 Minutes, DPRK-Linked Actors Suspected

N
News Editor 01
2026-07-08 15:58:13
Drift Protocol lost about $286 million in a highly coordinated attack that allegedly combined fake collateral, social engineering, and Solana durable nonce mechanics. Security firms linked the incident to DPRK-associated actors.
Drift ProtocolSolanaDeFi securityDPRKLazarus Group

A Major Security Breach Hits Drift Protocol

Drift Protocol, a leading decentralized perpetual futures exchange on Solana, suffered one of the most significant DeFi security incidents of 2026 after attackers allegedly drained roughly $286 million in about 12 minutes on April 1. In the aftermath, the protocol’s total value locked reportedly collapsed from around $550 million to below $250 million in a single morning, later stabilizing near $232 million. The project’s native token, DRIFT, also fell sharply in the following hours, dropping about 37% to 42% and bottoming in the $0.04 to $0.05 range.

What makes the case especially notable is that reports did not describe it as a simple smart contract coding bug. Instead, the attack appears to have been a carefully staged, multi-week operation involving fake collateral creation, governance manipulation, pre-signed transactions, and human-layer compromise. The incident has quickly become one of the most discussed topics in crypto security circles.

How the Attack Was Allegedly Prepared

According to reports cited in the source material, the operation may have started with an ETH withdrawal from Tornado Cash on March 11. Those funds were then allegedly used to deploy a token called carbonvote (CVT) on March 12. Blockchain analysts noted that the deployment timestamp aligned with approximately 9:00 a.m. in Pyongyang, a detail that immediately drew attention from investigators tracking state-linked threat patterns.

Over the following three weeks, the attacker reportedly built a small amount of liquidity for CVT on Raydium and used wash trading to keep the token’s price close to $1.00. Drift’s oracle system allegedly accepted that market price as legitimate. In effect, the attacker appears to have manufactured collateral that looked real enough for automated systems to treat as valid.

Drift later said that the unauthorized access involved an “innovative attack” using durable nonce accounts. The project described the incident as a sophisticated, phased operation that included the use of pre-signed transactions whose execution could be delayed until the attacker was ready.

The Governance Weak Point

The most consequential step appears to have occurred between March 23 and March 30, when the attacker allegedly shifted from market setup to social engineering. Using Solana’s legitimate durable nonce functionality, the threat actor reportedly convinced members of Drift’s security council multisig to pre-sign transactions that looked routine. Those signatures effectively became ready-to-use authorization keys, stored until the timing was optimal.

A critical opportunity opened on March 27, when Drift migrated its security council to a 2-of-5 signing threshold and removed its timelock. In DeFi governance, timelocks are commonly used to enforce a delay of 24 to 72 hours before privileged actions take effect, giving the community and security monitors time to spot suspicious changes and respond. Once that protection was removed, the attacker allegedly gained the ability to execute administrative actions immediately. The previously signed transactions could then be triggered without delay.

This detail has become one of the clearest lessons from the incident: a protocol may have sophisticated architecture, but if governance protections are weakened, weeks of preparation can be converted into an almost instant cash-out event.

The 12-Minute Drain

On April 1, the attacker allegedly activated the pre-signed transactions, listed CVT as approved collateral, raised withdrawal limits, and deposited massive quantities of the token. Drift’s risk engine then treated that collateral as valid and released real assets against it. Reports say the protocol handed over millions of dollars worth of JLP, USDC, and SOL, along with smaller amounts of wrapped bitcoin and ether.

In total, 31 withdrawal transactions were reportedly settled in roughly 12 minutes. That speed highlights the danger of combining manipulated collateral with governance-level access. Once the permissions were in place and the fake collateral was recognized by the system, the outflow of real funds became brutally efficient.

Post-Exploit Laundering and On-Chain Response

After the theft, the stolen assets were reportedly swapped into USDC through Jupiter, bridged to Ethereum, and then converted into tens of thousands of ETH. Some of the funds were said to have been routed through Hyperliquid, while another portion allegedly moved directly to Binance. These rapid laundering steps further reinforced suspicions that the attackers were experienced operators with established post-exploit playbooks.

On April 3, Drift sent an on-chain message from an Ethereum address to four wallets said to be controlled by the hackers. The message was brief: “We are ready to talk.” As of the timeframe described in the source material, no comprehensive reimbursement plan had been announced.

DPRK Attribution Gains Attention

Security firms Elliptic and TRM Labs linked the attack to threat actors associated with North Korea (DPRK). Their reasoning reportedly included the Tornado Cash origin of funds, the deployment timing that matched Pyongyang working hours, the heavy reliance on social engineering, and the speed and structure of the laundering activity after the hack.

Observers also drew comparisons to the methods used in the 2022 Ronin bridge hack, which U.S. authorities attributed to the Lazarus Group. In both cases, the pattern emphasized patience, operational staging, and exploiting human processes rather than depending purely on a novel code vulnerability. The source material also noted that the U.S. government has linked such thefts to the financing of North Korea’s weapons programs, while Elliptic tracked more than $300 million stolen in the first quarter of 2026 alone.

Contagion Across the Ecosystem

The consequences extended well beyond Drift itself. Reports said the fallout reached more than 20 protocols. Prime Numbers Fi disclosed multi-million-dollar losses. Carrot Protocol halted mint and redeem functions after about 50% of its TVL was affected. Pyra Protocol disabled withdrawals entirely, leaving user funds inaccessible at the time of reporting. Piggybank reportedly lost $106,000 and reimbursed users from its team treasury.

The event also triggered scrutiny around risk controls in Solana-based DeFi more broadly. Not every firm was exposed. DeFi Development Corp., a Nasdaq-listed company with a Solana treasury strategy, stated on April 1 that it had no exposure to Drift because its internal risk framework had excluded the protocol entirely.

The Main Lesson for DeFi

The Drift incident underscores a point the industry has long understood but has not always consistently enforced: timelocks are not optional. Removing a governance delay may appear operationally convenient, but it can eliminate one of the few practical defenses against both insider misuse and socially engineered administrative compromise.

The case also shows that DeFi security can fail at the intersection of market structure, oracle assumptions, multisig procedures, and human trust. A fake token with carefully maintained pricing, combined with durable nonce mechanics and pre-signed approvals, created a path for draining real assets without relying on a straightforward protocol bug. That makes the incident especially important for security teams, governance designers, and users assessing counterparty risk.

As of April 3, Drift was still in the critical early phase of trying to preserve user confidence and define a recovery path. Whether the protocol can regain trust may depend not only on reimbursement and communication, but also on whether it can prove that governance and operational safeguards will be fundamentally rebuilt. For the broader crypto industry, the exploit may stand as one of 2026’s defining reminders that protocol security is never just about code.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.