Blockchain analytics firm Elliptic reported Thursday that the $286 million exploit of Drift Protocol, a decentralized perpetual futures exchange on Solana, carries multiple indicators pointing to state-sponsored North Korean hackers. The incident is the largest crypto theft so far in 2026.
Elliptic identified specific onchain behavior, laundering methods, and network-level signals aligning with previous DPRK-linked attacks. If confirmed, this would be the 18th such act Elliptic has tracked this year, with over $300 million stolen in total.
Token Crash and Onchain Signals
Drift Protocol's native token DRIFT has plunged more than 40% since the hack, currently trading around $0.06. The exchange is the largest perpetual futures platform on Solana, and the exploit has severely shaken user confidence.
Elliptic noted that the attack “is a continuation of the DPRK’s sustained campaign of large-scale cryptoasset theft,” which the U.S. government has linked to funding its weapons of mass destruction programs. Hours after the hack, Arkham data showed over $250 million moving from Drift to an intermediary wallet and then to multiple addresses.
Record Year for DPRK Hacks
In December 2025, Chainalysis reported that DPRK hackers stole a record $2 billion in crypto that year, including the $1.4 billion Bybit breach—a 51% increase from 2024. The U.S. Treasury last month reiterated that North Korea uses stolen crypto to fund its weapons programs.
Elliptic’s analysis highlights a familiar operational pattern: “premeditated and carefully staged” activity with test transactions and pre-positioned wallets preceding the main event. Once the exploit executed, funds were rapidly consolidated, swapped, bridged across chains, and converted into more liquid assets.
Laundering Challenges: Cross-Chain and Account Clustering
Elliptic emphasized a central challenge posed by Solana’s account model. Because each asset is stored in a separate token account, activity from a single actor can appear fragmented across multiple addresses. Without linking these accounts, investigators see only “fragments of the attacker’s activity, not the complete picture.”
The firm applied a clustering approach to connect token accounts back to a single entity, enabling exposure identification regardless of which address is screened. The incident also underscores the cross-chain nature of modern laundering—funds moved from Solana to Ethereum and beyond—requiring what Elliptic calls “holistic cross-chain tracing capabilities.”

