Drift Protocol, one of Solana’s largest decentralized perpetual futures exchanges, was hit by a major exploit on April 1, 2026, with attackers draining $286 million in roughly 12 minutes. The incident quickly became one of the most discussed security events in crypto, not only because of the size of the loss, but also because of the method: a multi-week operation built around fake collateral, governance manipulation, and social engineering rather than a straightforward smart contract bug.
In the immediate aftermath, Drift’s total value locked fell from around $550 million to below $250 million, later settling near $232 million. The project’s native token, DRIFT, also came under heavy pressure, dropping 37% to 42% within hours and briefly bottoming in the $0.04 to $0.05 range.
How the attack appears to have been prepared
Reports cited in the source material suggest the exploit was not triggered by a conventional coding flaw. Instead, the attacker allegedly began by withdrawing ETH from Tornado Cash on March 11. That capital was then used to deploy a token called carbonvote (CVT) on March 12. Blockchain analysts reportedly noted that the deployment timestamp aligned with roughly 9:00 a.m. Pyongyang time, which immediately drew attention in the context of known North Korean-linked tradecraft.
Over the following three weeks, the attacker is said to have built a thin layer of liquidity for CVT on Raydium and maintained its price near $1.00 through wash trading. Drift’s oracle system then accepted that price as valid. In effect, the attacker created a form of synthetic or fake collateral that looked legitimate to automated systems watching on-chain pricing and liquidity conditions.
This phase was important because it laid the foundation for the actual drain. By the time the exploit was executed, CVT could be presented to the protocol as though it were a legitimate asset with market value, even though that value had allegedly been manufactured through controlled trading activity.
Durable nonce and the governance angle
The Drift team said the malicious actor gained unauthorized access through an attack involving durable nonce accounts, a legitimate Solana feature that allows transactions to be signed in advance and executed later. According to the reporting, the attacker shifted from technical setup to the human layer between March 23 and March 30, persuading members of Drift’s security council to pre-sign transactions that appeared routine.
Those signatures effectively became stored authorization tools that could be activated later. The critical governance change reportedly came on March 27, when Drift migrated its security council to a 2-of-5 signing threshold and removed its timelock. Timelocks are designed to delay sensitive administrative actions, often by 24 to 72 hours, so communities and monitoring systems have time to spot suspicious changes and potentially intervene.
Once that safeguard was removed, the attacker no longer faced a meaningful delay between privileged action and execution. The pre-signed transactions could be used immediately, turning weeks of preparation into a rapid extraction event.
The 12-minute drain
On April 1, the attacker reportedly activated the prepared transactions, listed CVT as valid collateral, raised withdrawal limits, and deposited hundreds of millions of CVT into the protocol. Drift’s risk engine then released real assets against that collateral. Those assets reportedly included millions in JLP, millions in USDC, millions in SOL, and smaller amounts of wrapped bitcoin and ether.
According to the source, 31 withdrawal transactions were settled within about 12 minutes. After the assets were extracted, the attacker swapped stolen tokens into USDC using Jupiter, bridged funds to Ethereum, and converted part of the haul into tens of thousands of ETH. Some funds reportedly moved through Hyperliquid, while another portion was sent directly to Binance.
On April 3, Drift sent an on-chain message from an Ethereum address to four wallets believed to be controlled by the attackers. The message was brief: “We are ready to talk.”
Why investigators suspect DPRK-linked actors
Security firms Elliptic and TRM Labs reportedly attributed the attack to threat actors linked to the Democratic People’s Republic of Korea (DPRK). Their reasoning included the use of Tornado Cash, the timing of token deployment, the social-engineering-heavy structure of the intrusion, and the speed of post-exploit laundering.
These characteristics fit a pattern long associated with Lazarus-linked operations: patient preparation, manipulation of human processes, rapid monetization, and cross-chain laundering. The source specifically compares the method to the approach used in the Ronin bridge hack in 2022, another landmark crypto theft tied to North Korean actors.
The report also notes that U.S. authorities have repeatedly linked such thefts to the financing of North Korea’s weapons programs. Elliptic reportedly tracked more than $300 million in crypto thefts in the first quarter of 2026 alone, underscoring the scale of the broader threat landscape.
Contagion across the Solana DeFi ecosystem
The damage did not stop with Drift. More than 20 protocols were reportedly affected by the fallout. Prime Numbers Fi disclosed losses of several million dollars. Carrot Protocol halted mint and redeem functions after about 50% of its TVL was impacted. Pyra Protocol disabled withdrawals entirely, leaving user funds inaccessible at least as of April 3. Piggybank reportedly lost $106,000 and reimbursed users from its team treasury.
The event also prompted statements from firms seeking to clarify exposure. DeFi Development Corp., a Nasdaq-listed company pursuing a Solana treasury strategy, said on April 1 that it had no exposure to Drift because its risk framework had excluded the protocol.
The key lesson: timelocks are not optional
One of the clearest takeaways from the incident is that timelocks are a core governance defense, not a convenience feature. The source argues that removing this single layer of protection on March 27 transformed a complex, multi-stage attack into a 12-minute cash-out. In decentralized systems, especially those relying on multisig councils and privileged administrative actions, delayed execution is often the only practical window for the community to identify and react to suspicious changes.
The Drift case also highlights the risk of treating legitimate blockchain features as inherently safe. Durable nonce accounts are not malicious on their own, but in the hands of a sophisticated attacker, they can become tools for storing future authorization. Combined with social engineering and weakened governance controls, that created a highly effective attack path.
What comes next
As of April 3, Drift had not announced a comprehensive reimbursement plan. That leaves several open questions for users and the wider market: whether the stolen assets can be frozen or partially recovered, whether affected users across interconnected protocols will be made whole, and whether Solana DeFi projects will now tighten standards around oracle listing, collateral onboarding, multisig governance, and delayed admin execution.
The exploit is already being discussed as a defining DeFi security case of 2026. Not simply because of the amount lost, but because it showed how operational security, governance design, and human trust can fail together. For protocols across crypto, the Drift incident is a reminder that the most damaging attacks do not always begin with broken code. Sometimes, they begin with a normal-looking signature, a trusted process, and a safeguard quietly removed.

