Inside the Six-Month Infiltration Behind Drift Protocol's $285 Million Solana Exploit
Helius CEO Mert was the first to raise an alarm. On the morning of April 1st, he posted publicly that Drift "might be getting exploited," though he stopped short of certainty. Minutes before that post, he had already privately contacted Circle, telling the stablecoin issuer there was a "high likelihood of a potentially large exploit" and asking someone to respond urgently. Circle gave no public reply.
Twenty minutes on, researcher Vladimir S. supplied hard numbers: two addresses had already moved roughly $200 million worth of SOL, and — critically — the underlying exploit appeared to have been quietly running for a full week before anyone noticed.

PeckShield then pushed a public alert directly at Drift. Drift's own acknowledgment followed roughly an hour after the first public warnings, stating: "We are observing unusual activity on the protocol. We are currently investigating. Please do not deposit funds into the protocol while we investigate. This is not an April Fools joke." The disclaimer was necessary — landing on April 1st, the initial warning was widely dismissed as a prank by early readers.
Shortly afterward, Drift confirmed an active attack, froze deposits and withdrawals, and said it was coordinating with multiple security firms, bridges, and exchanges, again noting the timing was not a joke. By that point, Arkham Intelligence had already traced more than $268 million moving out of Drift's vault into an intermediary wallet, identified on Arkham as 98e28143-3e15-4e2a-8527-f30d4c7c11aa.
The vault balance fell from $309 million to $41 million, and has since dropped further — it currently sits near $8 million. Meanwhile the attacker was already converting proceeds into ETH. By the time Drift's confirmation landed, the drain itself was effectively complete — raising questions about what the protocol's monitoring was actually catching in real time.
01A Setup Ten Days in the Making — At Least
Despite the sudden appearance on April 1st, the operation had begun on March 23rd. What eventually surfaced was a three-part scheme, each piece worthless without the others, built openly over roughly ten days. It wasn't a conventional hack so much as an engineered confidence scheme.
Component one: a fabricated collateral asset. Three weeks before the drain, on March 12th, the attacker launched a Solana token called CarbonVote Token (CVT) — listed on Dex Screener — minting 750 million units for $1.19 and seeding a Raydium pool with just $500. From there, the attacker wash-traded the token between wallets they controlled, building a synthetic price history hovering around $1. The oracle feeding that price into Drift was itself deployed and controlled by the attacker, so by the time the attack went live, CVT carried weeks of seemingly legitimate price history — the mint address is G84LEhbNMR1yYbHgHbnNYNSK8mpTKcazh5jcW5yMPQKo. A theft that would ultimately reach $285 million was seeded with roughly $501.19.
Component two: durable nonce accounts as delayed-action triggers. Solana's durable nonce feature allows a transaction to be pre-signed and executed later, bypassing the standard short expiry window — a legitimate mechanism intended for multisig coordination and offline signing. The attacker repurposed it as a timed trigger. On March 23rd, four durable nonce accounts were established: two under the attacker's control (CZRBcHAvXU6TzzjGuG4rT98UuTR7PBUeSGPZRDW5mfYW, 48cV6Mw5Y5afT8ofukvtFaMtrsCohHhsv8MfbdW8agh3) and two tied to legitimate members of Drift's Security Council multisig (45cZ5Fj97Va5Abipr6NN8Zf1BqZqWneSek1hU5cQRvhw, 39JyWrdbVdRqjzw9yyEjxNtTbTKcTPLdtdCgbz7C7Aq8).
In the days after those accounts were set up, Drift carried out a previously planned migration of its Security Council, swapping in four new signers of five and dropping the approval threshold from 3-of-5 to 2-of-5. Within days of that new multisig activating, the attacker had already secured a pre-signed nonce from one of the incoming signers — nonce account 6UJbu9ut5VAsFYQFgPEa5xPfoyF5bB5oi4EknFPvu924. The multisig was one week old, and the attacker effectively controlled two of its five keys.
Component three: the human vector. Making the nonce scheme work required legitimate signers to pre-approve transactions without fully grasping what they were authorizing. Drift's own statement described it as "targeted social engineering or transaction misrepresentation" — the signers approved something, just not what they believed they were approving.
One coincidence worth flagging without over-reading it: on March 25th, Drift co-hosted "Liquid Hours NYC" with AWS and Failsafe during DAS NYC, and the attacker's initial funding transactions landed roughly twelve hours before that event began. Whether the two are connected is not established.
What is established is the funding trail itself: the entire operation was financed from Tornado Cash three weeks earlier, with 10 ETH bridged from Ethereum to Solana via LiFi and NEAR intents before being split across multiple wallets ahead of April 1st. The origin transaction is 0x14cd918f2c1ffcd9a96f9d2ccd1988469fd246a3ed4e3565d2fa5b5b91238ba1.
A separate detail surfaced afterward: Neodyme's 2024 security audit of Drift had examined the protocol's admin authority — including the ability to initialize markets and adjust parameters — but according to Vladimir S., who reviewed the audit after the hack, that authority structure wasn't flagged as critical, medium, or low severity. It was apparently accepted as part of the protocol's baseline trust assumptions. No audit is designed to catch a stolen private key, but this particular risk had been examined directly and left unaddressed.
02From Admin Transfer to Empty Vaults in 128 Seconds
The preparation spanned weeks; the execution took barely two minutes. One minute after Drift ran a routine test withdrawal from its own insurance fund on the afternoon of April 1st, the pre-signed nonce transactions executed — two transactions, four slots apart, transferring admin control: the create-and-approve transaction and the approve-and-execute transaction. Drift's State account now belonged to the attacker, at address 5zpq7DvB6UdFFvpmBPspGPNfUGoBRRCE2HHg5u3gxcsN.
In that same slot, a new collateral market was created for CVT with maximally permissive parameters, and updateWithdrawGuardThreshold() was invoked across five markets, pushing withdrawal caps up to 500,000,000,000,000 — effectively erasing every safety limit.
What followed took 128 seconds total. At the 25-second mark, the attacker opened a Drift user account under a key they controlled. Three seconds later, they deposited 500 million CVT into spot market index 63 — the very collateral market the compromised admin key had just created with loose parameters. The deposit was nearly free, since CVT had no real market value, but the inflated collateral weighting let the attacker borrow against it as though it were genuinely valuable.
Starting at the 30-second mark, withdrawals drained 18 different tokens across multiple vaults:
- JLP: 42.72M tokens — $159,350,000
- USDC: 71.42M — $71,420,000
- cbBTC: ~164.35 BTC — $11,290,000
- USDT: 5.65M — $5,650,000
- USDS: 5.25M — $5,250,000
- WETH: 2,200.59 — $4,690,000
- dSOL: 45,292.21 — $4,470,000
- WBTC: 63.47 — $4,360,000
- Fartcoin: 23.37M — $4,110,000
- JitoSOL: 33,976.51 — $3,600,000
- syrupUSDC: 2.87M — $3,320,000
- INF: 21,241.62 — $2,500,000
- mSOL: 17,418.92 — $1,990,000
- bSOL: 9,474.33 — $1,020,000
- EURC: 583,980.69 — $677,420
- zBTC: 8.61 — $586,790
- USDY: 477,375.42 — $539,430
- JUP: 2.62M — $431,440
The confirmed total came to $285.26 million. The JLP vault was hit first and hardest at $159 million; cbBTC was left holding roughly 0.16 BTC. By the 128-second mark, the vaults had been substantially emptied.
Funds moved through an executor wallet, 55udxhScWQxM7cC9d1NPBQoEDC7B38w81EWKPZsM7ZCW, into a primary receiving address, HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES, then a secondary consolidation wallet, 8ubo4HbWJHKyFJYJc2Gh74dxCP7bN7Fu2Pi13KZ9rGxw.
The exit that followed was methodical. Some assets were swapped via Jupiter on Solana into USDC, WSOL, WBTC, and WETH, then moved to Ethereum through Circle's Cross-Chain Transfer Protocol across more than 100 transactions over roughly six hours. SOL took a separate path, bridged to Ethereum via Chainflip to address 0xd91a122b585bc588c9a48d0995ee0d7b4f8ab7dd, splitting the trail across platforms. On Ethereum, proceeds were consolidated into ETH across four addresses: 0xD3FEEd5DA83D8e8c449d6CB96ff1eb06ED1cF6C7, 0xAa843eD65C1f061F111B5289169731351c5e57C1, 0xbDdAE987FEe930910fCC5aa403D5688fB440561B, and 0x0FE3b6908318B1F630daa5B31B49a15fC5F6B674.
In summary: roughly three weeks of groundwork, one minute of compromised admin access, 128 seconds to strip the vaults, and roughly six hours of daytime bridging — all while stolen USDC moved through Circle's own rails unimpeded.
03Six Hours of Silence from Circle
For about six hours, roughly $230 million in stolen USDC burned on Solana and minted on Ethereum through Circle's CCTP across more than 100 transactions, during US business hours on a Tuesday afternoon. Circle froze none of it.
ZachXBT was blunt about it: "Circle was asleep while many millions of USDC was swapped via CCTP from Solana to Ethereum for hours from the 9 figure Drift hack during US hours. Value was moved and nothing was done yet again." Researcher Specter added a detail that undercut any excuse: the attacker parked the stolen USDC across several wallets for one to three hours before moving it, sitting on it in plain view. The attacker also deliberately avoided converting to USDT during bridging, seemingly betting that Circle wouldn't intervene. That bet paid off.
The timing made the inaction sting more. Nine days earlier, Circle had frozen USDC across 16 unrelated hot wallets — belonging to businesses, exchanges, casinos, forex firms, and a DFINITY bridge contract serving thousands of users — as part of a sealed US civil suit, without public explanation. One of those wallets, belonging to Goated.com, was quietly unfrozen three days later; most others remained locked as of April 2nd. ZachXBT had already labeled that earlier freeze "incompetent". Nine days after that episode, the same freezing infrastructure watched a confirmed nine-figure theft pass through without acting. Circle has issued no public response to the criticism.
As trader molu put it: "Circle could freeze it. But they're not required to." That distinction — capability versus obligation — is the gap the Drift incident exposed. Frameworks like the proposed GENIUS Act might eventually close it, but on April 1st no rule compelled Circle to act, and it didn't.
The stablecoin question wasn't the only fallout. At least 20 protocols reported disruptions, pauses, or losses tied to the exploit, with several halting deposits, withdrawals, or specific features while checking their exposure.
04A Governance Structure Everyone Now Recognizes as Thin
The day after the exploit, comparisons of multisig configurations across Solana lending protocols began circulating. Drift's setup — a 2-of-5 multisig with no timelock — meant any two signers could push through instant, irreversible admin changes with no review window and no circuit breaker. Analyst Fabiano laid out the comparison:
- Jupiter Lend: 4/7 multisig, 12-hour timelock
- Kamino: 5/10 multisig, 12-hour timelock
- Solstice: 3/5 multisig, 1-day timelock
- Loopscale: 3/5 multisig, timelock not listed
- Exponent: 2/3 multisig, timelock not listed
- Drift: 2/5 multisig, no timelock
Chaos Labs founder Omer Goldberg summarized the structural failure: the signer key held full authority over market creation, oracle assignment, and withdrawal limits, with no timelock, no broader multisig protection, and no built-in delay. He noted the full sequence ran in under 15 seconds.
Uniswap founder Hayden Adams was more pointed: "We have to stop letting centralized things call themselves DeFi. Admin key can drain all funds? CeFi. Otherwise DeFi means nothing and it's brand is destroyed." Cube Exchange framed the broader pattern: "The threat model FTX made obvious, custodial risk, concentrated authority, opaque internal controls, did not disappear when the industry switched from CeFi to DeFi. It just moved from a CEO's discretion to an admin key's permissions."
05The Ten-Day Story Was Really a Six-Month Operation
What the on-chain record showed — nonce accounts set up March 23rd, a multisig migration days later, execution on April 1st — looked like a tidy ten-day operation. It wasn't. Drift's Incident Background Update, published April 4th, revealed a campaign that had actually run for roughly six months, resembling an organized intelligence operation more than a typical exploit.
It began at a conference around October 2025, when a group presenting itself as a quantitative trading firm approached Drift contributors expressing interest in integrating with the protocol. They were technically credible — plausible professional histories, real familiarity with how Drift functioned — and they set up a Telegram channel from that first meeting that stayed active. Over subsequent months they kept reappearing at industry events across multiple countries, gradually becoming known contacts rather than strangers — a working relationship built over close to half a year.
Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, which involved filling out strategy documentation and engaging directly with contributors. They committed more than $1 million of their own capital, joined working sessions, and asked substantive, well-informed questions — behaving exactly as a legitimate integrating firm would. By February and March 2026, they were established, familiar contacts, not newcomers.
That's when the technical vector appeared. As integration talks progressed, the group began sharing code repositories and applications, presented as frontend deployments for their vault and a wallet product still in beta. A contributor is believed to have cloned a shared repository; another may have installed a TestFlight build presented as the group's wallet app. Drift has not confirmed which vector actually succeeded — both remain under forensic review. On the repository path, Drift pointed to a known flaw in VSCode and Cursor, widely used code editors, that security researchers had flagged since late 2025: merely opening a file or folder could silently execute code, with no click and no permission prompt required.
Once inside a contributor's device, the attackers gained access to signing workflows — enabling the multisig pre-approvals, the durable nonce accounts, and the entire March 23rd setup described earlier. In effect, the on-chain exploit was only the final act of a much longer campaign. Immediately after the April 1st drain, the group erased its tracks: Telegram history deleted, malicious tooling wiped, and the "trading firm" ceased to exist.

Working with the SEAL 911 security team, Drift assessed with medium-high confidence that the operation was run by UNC4736, a North Korea-linked group also known as AppleJeus or Citrine Sleet. The attribution rests on on-chain fund flows tracing back to actors behind the October 2024 Radiant Capital hack, plus overlapping personas linked to known DPRK activity. Drift was careful to note that the individuals who appeared in person were not themselves North Korean nationals — DPRK operations at this level rely on third-party intermediaries with fabricated identities, employment records, and professional networks built to withstand scrutiny.
The approach is not new. In October 2024, Radiant Capital lost roughly $53 million after attackers posing as a former contractor delivered malware via a Telegram-shared ZIP file. The Drift campaign followed the same template at roughly six times the dollar value and six times the patience.
Security researcher Taylor Monahan of MetaMask didn't mince words about the wider implication: "Lots of DPRK IT workers built the protocols you know and love, all the way back to DeFi summer." She said she believes at least 40 DeFi platforms have had North Korean IT workers embedded at some point, adding that fabricated resumes citing years of blockchain development experience "is not a lie," and warning that the sophistication seen here "makes me think they already have multiple other teams on lock."
ZachXBT distinguished this from cruder tactics: "Threats via job postings, LinkedIn, email, Zoom, or interviews are basic and in no way sophisticated, the only thing about it is they're relentless. If you or your team still falls for them in 2026, you're very likely negligent." Attorney Ariel Givner went further, calling it potentially "a civil negligence issue" and adding: "In plain terms, they failed their basic duty to protect the money they were managing. You can't just shrug, say 'state hackers did it,' and leave users holding the bag. People trusted Drift with their funds… not with playing risky games against pro attackers."
With Elliptic, TRM Labs, and Drift's own investigation all converging on a DPRK attribution, this becomes the eighteenth such operation Elliptic has tracked in 2026 alone, pushing North Korean-linked crypto theft past $300 million for the year before April had even ended.
06Aftermath
Drift sent on-chain messages to the four addresses holding stolen funds, asking the holders to make contact via Blockscan. No compensation plan has been announced. Drift is working with Asymmetric Research and OtterSec on a coordinated recovery effort and will participate in the Solana Foundation's STRIDE program.
On April 9th, Drift posted an interim update: "We recognize the impact this has had across our users and the builders who have integrated with us - many of whom rely on Drift as core infrastructure. We're actively working on next steps and will share more once details are finalized."
Immunefi data suggests that 83% of native tokens from hacked protocols never return to their pre-hack prices — not necessarily a technical failing, but a reflection of how hard it is to rebuild trust once broken at scale. Drift had already shed $1 billion in TVL since its October peak before this attack, leaving it with less cushion than most protocols facing a similar hit.
The method lines up with other major DPRK-linked incidents: Bybit lost $1.5 billion, Ronin lost $625 million, and Radiant Capital's roughly $53 million loss functioned as an earlier dry run for this same playbook. North Korean-linked hackers have now stolen more than $6.75 billion in crypto in total, with the pace increasing as operations grow longer and harder to detect until after they've concluded.
Private key compromises accounted for 88% of all stolen crypto in Q1 2025, and social engineering remains the entry point behind nearly every major theft in the industry — a pattern the industry acknowledges after each incident and then largely sets aside once the initial shock fades.
Ethereum educator Patrick Collins called this the most alarming hack of 2026, more unsettling than Bybit despite the smaller dollar figure, not because of the technical mechanism but because of what it demonstrated: "Meeting somebody in person isn't going to be the obstacle we historically thought it would be."
The total losses — roughly $285 million, funded initially by just 10 ETH pulled from Tornado Cash — underscore a broader takeaway: the failure here wasn't a flaw in Drift's code, but a six-month effort to compromise the people around it. Somewhere else right now, another protocol is likely running a similarly thin multisig, another contributor may be weighing a GitHub invite from a friendly, technically fluent stranger met at a conference, and another testing link may be sitting unopened in a Telegram thread.
Get new scam files the moment we publish them — usually 2–3 emails a week.