Key takeaways
- Drift Protocol, Solana’s largest decentralized perpetual futures exchange, lost $286 million in an exploit on April 1, 2026.
- Blockchain analytics firm Elliptic attributes the attack to North Korean state-sponsored hackers based on laundering patterns and on-chain indicators.
- The attacker used a fake token, manipulated price oracles, and abused Solana’s “durable nonces” feature to pre-sign transactions weeks before execution.
- Circle faced sharp criticism for failing to freeze stolen USDC during a six-hour bridging window.
Published: April 2, 2026 14:00 UTC
How the attack unfolded
The exploit began weeks before the actual theft. According to a CoinDesk investigation, the attacker created a fake token called CarbonVote Token (CVT), seeded it with $500 in liquidity, and wash-traded it repeatedly to build an artificial but stable price history. On-chain price oracles eventually treated CVT as a legitimate asset worth roughly $1 per token.
A durable nonce is a Solana transaction feature that allows users to pre-sign transactions and execute them at a later time, bypassing the network’s usual requirement that transactions expire quickly.
The attacker secured two misleading approvals from Drift’s five-member Security Council multisig. Using those approvals, they pre-signed administrative transfer transactions via durable nonces that remained valid for over a week. On April 1, the attacker listed CVT as a valid market on Drift, raised withdrawal limits to extreme levels, and executed 31 rapid withdrawals in roughly 12 minutes.
The stolen assets included 41.7 million JLP tokens (approximately $155 million), along with USDC, SOL, cbBTC, wBTC, and liquid staking tokens. Most of Drift’s liquidity was gone within one hour.

North Korean hackers suspected
Blockchain analytics firm Elliptic identified the attack as consistent with North Korean state-sponsored operations. The on-chain behavior, laundering methods, and network-level indicators matched patterns from previous DPRK-attributed exploits.
If confirmed, this would be the eighteenth North Korean crypto operation Elliptic has tracked in 2026, pushing the year’s total above $300 million. North Korean hackers stole a record $2 billion in crypto during 2025, according to Chainalysis, including the $1.4 billion Bybit breach.
Stolen assets were consolidated, converted to USDC and SOL, then bridged from Solana to Ethereum using Circle’s Cross-Chain Transfer Protocol (CCTP). On Ethereum, the attacker swapped funds into ETH, accumulating 129,066 ETH across multiple wallets.
Circle under fire for slow response
On-chain investigator ZachXBT criticized Circle for failing to freeze the stolen USDC during a six-hour window while funds were being bridged. The bridging activity took place during U.S. business hours across more than 100 transactions, with no intervention from Circle.
ZachXBT contrasted this inaction with Circle’s recent decision to freeze 16 unrelated corporate hot wallets in a sealed U.S. civil case. Security researcher Specter noted the attacker held USDC across wallets for one to three hours before swapping, and deliberately avoided converting to Tether (USDT), suggesting confidence that Circle would not act. Circle has not publicly responded.
Market and protocol impact
The DRIFT governance token dropped more than 25% following the exploit, breaking below the $0.064 support level. Drift’s total value locked collapsed from approximately $550 million to under $300 million within hours. Bloomberg reported the incident as the largest DeFi hack of 2026 and the second-largest security incident in Solana’s history, behind only the $326 million Wormhole bridge exploit in 2022.
Immunefi data shows 83% of native tokens from hacked protocols never recover to pre-hack prices, raising questions about Drift’s long-term viability. The protocol has halted withdrawals while its team investigates and works with law enforcement.
What comes next
The Drift exploit is likely to accelerate several industry conversations. Solana’s durable nonce feature, designed for convenience, is now under scrutiny as a potential attack vector that other protocols may also be vulnerable to. The incident also raises fresh questions about multisig security: if two out of five council approvals can be deceived, the governance model needs review.
For Circle, the pressure to establish a clear, public framework for emergency USDC freezes is mounting. The company has frozen assets in past incidents but has no published criteria for when or how quickly it will act.
Drift’s team has not yet announced a compensation plan for affected users.
Frequently asked questions
What is Drift Protocol and why was it targeted?
Drift Protocol is the largest decentralized perpetual futures exchange on the Solana blockchain. It was targeted because of its high total value locked ($550 million before the attack) and vulnerabilities in its admin key governance and oracle systems that the attacker exploited over several weeks of preparation.
How did the attacker use durable nonces to steal from Drift?
Durable nonces are a Solana feature that lets users pre-sign transactions for later execution. The attacker obtained two misleading approvals from Drift’s Security Council, pre-signed administrative transfer transactions, and held them for over a week before triggering all 31 withdrawals in 12 minutes.
Can the stolen Drift Protocol funds be recovered?
Recovery is uncertain. The attacker bridged funds to Ethereum and converted them to 129,066 ETH across multiple wallets. Circle did not freeze the USDC during transit. Drift’s team is working with law enforcement and blockchain analytics firms, but North Korean state-sponsored hackers have historically been difficult to trace and recover funds from.








