Drift Protocol, the largest decentralized perpetual futures exchange on Solana, lost $285 million on April 1 after an attacker exploited a legitimate blockchain feature to bypass the protocol’s security controls. Blockchain analytics firm Elliptic has linked the attack to North Korean state-sponsored hackers, marking what would be the DPRK’s eighteenth confirmed crypto operation in 2026.
A decentralized perpetual futures exchange is a platform where traders can bet on the future price of crypto assets without an expiration date, and without relying on a centralized company to hold their funds.
Key takeaways
- Drift Protocol lost $285 million in the largest DeFi hack of 2026, executed on April 1 using pre-signed transactions and a compromised admin multisig.
- Elliptic identified on-chain laundering patterns consistent with North Korean state-sponsored operations, which have now stolen over $300 million in 2026 alone.
- The attacker used Solana’s “durable nonce” feature to pre-sign administrative transactions weeks before executing them, bypassing time-based security controls.
- Circle faced criticism from security researchers for failing to freeze stolen USDC as it was bridged from Solana to Ethereum over a six-hour window.
Published: April 2, 2026 12:00 UTC
How the attack worked
The exploit did not target a flaw in Drift’s smart contract code. The attacker used “durable nonces,” a legitimate Solana transaction feature that allows users to pre-sign transactions without the usual 60-to-90-second expiration window. This let the attacker prepare administrative transfers weeks in advance.
The full attack combined three elements: pre-signed durable nonce transactions, social engineering that obtained multisig approvals from legitimate Security Council members, and a manipulated oracle price from a fabricated token called CarbonVote Token (CVT). Drift’s Security Council operated on a 2-of-5 multisig configuration with no timelock, meaning only two compromised signatures were needed to authorize changes.
Once the attacker gained admin-level control, they disabled withdrawal limits and circuit breakers, introduced a fraudulent withdrawal mechanism, and drained the protocol’s vaults. On-chain data shows the attacker’s wallet was created eight days before the exploit and received a small test transfer from a Drift vault during that period, confirming this was a carefully staged operation.
The entire drain took less than an hour. Drift’s total value locked fell from roughly $550 million to under $300 million, and the DRIFT token dropped more than 40%.
North Korea attribution and fund movement
Elliptic published its analysis on April 2, citing on-chain behavior, laundering methodologies, and network-level indicators consistent with techniques observed in previous DPRK-attributed operations. If confirmed, Drift would be one of at least 18 North Korean crypto operations tracked this year, with total 2026 theft exceeding $300 million.
Security researcher Vladimir S. compiled a breakdown of stolen assets: $155.6 million in JLP tokens, $60.4 million in USDC, $11.3 million in CBBTC (Coinbase wrapped bitcoin), $5.65 million in USDT, $4.7 million in wrapped ether, $4.5 million in DSOL, $4.4 million in WBTC, and $4.1 million in FARTCOIN, with smaller amounts across other tokens.
The attacker used Jupiter, a Solana-based DEX aggregator, to swap stolen assets into stablecoins, then bridged more than $230 million in USDC from Solana to Ethereum using Circle’s Cross-Chain Transfer Protocol (CCTP). From there, portions were converted into ETH while some funds moved through centralized exchanges. This pattern mirrors previous DeFi exploits where attackers quickly bridge assets across chains to complicate recovery.
Circle’s delayed response draws criticism
On-chain investigator ZachXBT publicly criticized Circle for not freezing the stolen USDC during a roughly six-hour window while the funds were being bridged. He pointed out that the transfers happened during U.S. business hours, and that Circle had recently demonstrated its ability to freeze assets by locking 16 corporate hot wallets in a sealed civil case.
“Millions in stolen USDC bridged from Solana to Ethereum via CCTP while Circle sat on their hands,” ZachXBT wrote. The contrast between Circle’s rapid response in a civil matter and its inaction during one of the year’s largest thefts raised questions about the company’s incident response priorities and the responsibilities of stablecoin issuers during active exploits.
What comes next
Drift’s team says it is working with law enforcement and security partners on recovery. Some stolen USDC on Ethereum may still be recoverable, but the bulk of the $285 million loss remains outstanding.
The attack has reignited debate around multisig security practices in DeFi. Drift’s 2-of-5 Security Council configuration with zero timelock is a setup that security researchers have long flagged as insufficient for protocols holding hundreds of millions in user funds. Protocols like Aave and Compound use higher signature thresholds and mandatory timelocks on admin actions, which would have given Drift’s team time to detect and block the pre-signed transactions before execution.
For North Korea’s crypto operations, the Drift exploit continues a pattern that U.S. law enforcement has tied to weapons program funding. The FBI attributed the $1.5 billion Bybit hack in February 2025 to DPRK actors, and Elliptic’s data shows North Korean-linked hackers have stolen over $2 billion in crypto during 2025 alone. The pace has not slowed in 2026.
FAQ
What is a durable nonce on Solana and why did it matter in the Drift hack?
A durable nonce is a Solana feature that lets users pre-sign transactions without the normal 60-to-90-second expiration. In the Drift exploit, the attacker used this feature to prepare administrative transfers weeks before executing them, bypassing time-based security protections that would have otherwise invalidated the transactions.
How much did Drift Protocol lose in the April 2026 exploit?
Drift Protocol lost approximately $285 million in the exploit, making it the largest DeFi hack of 2026 and the second-largest security incident in Solana’s history after the $326 million Wormhole bridge exploit in 2022.
Why did Circle face criticism after the Drift Protocol hack?
Circle, the issuer of USDC, was criticized for not freezing stolen funds during a six-hour window while more than $230 million in USDC was bridged from Solana to Ethereum. On-chain investigator ZachXBT noted the transfers happened during business hours and that Circle had recently frozen wallets in an unrelated civil case, suggesting it had the capability to act.








