Drift Protocol loses $285M in largest DeFi hack of 2026

Drift Protocol 285 million DeFi hack on Solana blockchain

Key takeaways

  • Attackers drained approximately $285 million from Drift Protocol on Solana on April 1, making it the largest DeFi exploit of 2026.
  • The hack used Solana’s “durable nonces” feature combined with social engineering of Drift’s multisig Security Council, not a smart contract bug.
  • Blockchain analytics firms Elliptic and TRM Labs linked the attack to North Korean state-backed hackers based on laundering patterns.
  • Drift has paused all operations and is sending on-chain messages to Ethereum wallets holding roughly 129,000 ETH in stolen funds.

Published: April 3, 2026 12:00 UTC

Drift Protocol, the largest decentralized perpetual futures exchange on Solana, lost approximately $285 million in user assets on April 1 after attackers exploited a combination of social engineering and a legitimate Solana transaction feature called “durable nonces.” Blockchain analytics firms Elliptic and TRM Labs have both linked the attack to North Korean state-backed threat actors, which would make it the eighteenth DPRK-attributed crypto operation Elliptic has tracked this year.

A durable nonce is a Solana feature that replaces the standard expiring blockhash with a fixed one-time code, keeping a pre-signed transaction valid indefinitely until someone submits it on-chain.

How the attack worked

The exploit did not rely on a code vulnerability. Between March 11 and March 30, the attacker created multiple durable nonce accounts on Solana, then used social engineering to trick two of Drift’s five Security Council multisig signers into pre-approving transactions that appeared routine but contained hidden administrative authorizations.

Because durable nonces kept those pre-signed transactions valid for weeks, the attacker was able to separate the moment of approval from the moment of execution. On April 1, the attacker submitted the stored transactions in rapid sequence, seizing protocol-level administrative control in roughly 12 minutes.

The attacker also manufactured a fictitious asset called CarbonVote Token (CVT), seeded it with a few thousand dollars in liquidity, and conducted wash trades to give it the appearance of a real market. Drift’s oracles treated CVT as legitimate collateral worth roughly $785 million, allowing the attacker to borrow against it and drain real assets from the protocol’s vaults.

Solana DeFi security and durable nonces vulnerability

Why this is 2026’s biggest DeFi hack

At $285 million, the Drift exploit is the largest DeFi hack of 2026 and the second-largest security incident in Solana’s history, behind only the $326 million Wormhole bridge exploit in February 2022.

The attack stands out because of its patience and planning. On-chain staging began on March 11, nearly three weeks before execution. Attacker infrastructure, token manufacturing, and social engineering all ran in parallel, according to TRM Labs’ investigation. The stolen funds were consolidated and swapped into USDC and SOL, then partially bridged to Ethereum using Circle’s Cross-Chain Transfer Protocol. On Ethereum, portions were converted into ETH and spread across multiple wallets.

If confirmed as a DPRK operation, the Drift hack would push North Korea’s total crypto theft past $300 million for 2026 alone. Elliptic noted that the laundering methodologies and network-level indicators are consistent with known DPRK tradecraft from previous operations.

Drift’s response and fund recovery efforts

Drift immediately paused deposits, withdrawals, and trading after detecting the exploit. The protocol initiated a program upgrade to reclaim administrative authority and engaged security firms, exchanges, and law enforcement to trace and freeze the laundered funds.

On April 3, Drift escalated its recovery efforts by sending on-chain messages to four Ethereum wallets holding roughly 129,000 ETH tied to the stolen assets. The move signals that Drift is open to negotiated resolutions, a path other hacked protocols like Euler Finance and Poly Network have used in the past to recover stolen funds.

Whether the attackers will respond remains uncertain. North Korean hacking groups, particularly the Lazarus Group, have historically shown no interest in returning stolen crypto. The Ronin Bridge hack in 2022 ($620 million) and the Harmony Horizon Bridge exploit ($100 million) both resulted in permanent losses attributed to the same state-backed operation.

What comes next

The Drift hack is likely to accelerate scrutiny of multisig governance in DeFi protocols. The exploit exposed a specific weakness: protocols that rely on multisig signers to approve administrative actions without time-locks or contextual verification are vulnerable to pre-signed transaction attacks. Solana’s durable nonces, while useful for offline transaction signing and automated payments, become a weapon when combined with social engineering.

For Drift users, the immediate question is whether any funds can be recovered. For the broader Solana DeFi ecosystem, the question is whether other protocols using similar Security Council structures have the same exposure.

FAQ

What are durable nonces on Solana?

Durable nonces are a Solana feature that replaces the standard expiring blockhash in a transaction with a fixed one-time code. This keeps a pre-signed transaction valid indefinitely until it is submitted on-chain, rather than expiring after about 90 seconds like normal Solana transactions.

Can Drift Protocol users recover their funds?

Recovery is uncertain. Drift has paused operations and is sending on-chain messages to wallets holding stolen assets, but North Korean hacking groups have historically never returned stolen crypto. Security firms and exchanges are working to trace and freeze funds that moved through centralized platforms.

Is this connected to North Korea’s Lazarus Group?

Blockchain analytics firms Elliptic and TRM Labs both say the on-chain behavior, laundering patterns, and network indicators are consistent with previous DPRK-attributed operations. If confirmed, this would be the eighteenth North Korea-linked crypto operation tracked by Elliptic in 2026.

Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *