Drift Protocol, a decentralized exchange on Solana, lost about $285 million on April 1 after attackers used a compromised administrator key to drain nearly 20 vaults. The exploit unfolded in roughly 12 minutes across 31 transactions, making it one of the largest DeFi breaches tied to the Solana ecosystem in recent years.
On-chain data cited in the report and early alerts from PeckShield showed the attacker withdrew 66.4 million USDC, 42.7 million JLP, 23.3 million MOODENG, 5.6 million USDT, 5.2 million USDS, 2.6 million JUP, 583,000 RAY, and 477,000 WETH. A portion of the stolen JLP was burned, while much of the remaining haul was converted into SOL and spread across multiple wallets.
Compromised admin access bypassed internal controls
The attack did not rely on a bug in Drift’s smart contracts. According to the published details, the attacker used the compromised admin key to list CVT as a new spot market and then lifted withdrawal limits for USDC and four other markets to 500 trillion. That change effectively neutralized the platform’s internal protections and let the attacker use fraudulent collateral to withdraw funds from Drift’s spot market vaults.
Researchers also noted that different signing keys appeared across the 31 transactions. That points either to a breach in the key management setup or to multiple authoritative keys being accessed. It looks like a coordinated operation, not an opportunistic contract exploit.
Solana Foundation points to social engineering
Solana Foundation Chair Lily Liu said on X that the Drift incident had wide effects across the ecosystem and that the team was working around the clock on the investigation and response. She added that the smart contract itself had held up, and that the real target of the attack was “people,” describing it as an issue tied to social engineering and operational security weaknesses rather than code-level exploitation.
Solana Foundation Chief Product Officer Vibhu Norby made the same distinction on X, saying the incident was “not caused by a program or smart contract vulnerability” and was more likely linked to operational security or social engineering. He also said protocols that rely on multisignature mechanisms across chains can face similar exposure, while calling the Drift breach an isolated case rather than evidence of a systemic problem in Solana DeFi.
Token prices fell and cross-chain transfers faced delays
The fallout hit both Drift and the wider Solana market. DRIFT dropped from about $0.072 to $0.055 after the attack as users rushed to pull liquidity and the protocol halted deposits and withdrawals. SOL fell 9% to an intraday low of $78.60 on April 2, bringing its market capitalization down to $45.5 billion. The report also said SOL had already declined more than 10% over the previous seven days.
Wormhole said on X that user assets were not at risk and that bridge functionality remained live, but warned that some Solana cross-chain transfers could be delayed because built-in Solana security mechanisms had been triggered. The protocol said its core contributors were in contact with the broader Solana ecosystem team.
The incident adds to a growing list of crypto breaches rooted in phishing, impersonation, and operational access failures. In this case, the disclosed evidence points away from a broken contract and straight at privileged access and key security.

