Solana DeFi Platform Drift Investigates Suspected Attack, Urges Users to Halt Deposits
Drift is a major decentralized perpetual futures and lending platform on Solana, where users deposit assets as trading collateral. The attacker did not exploit a software vulnerability. Instead, social engineering was used to secure approval from the Security Council multisig before Solana's “durable nonce” mechanism was abused to seize administrative control, highlighting the human signing and governance risks facing DeFi platforms.
Drift confirmed the attack and suspended deposits and withdrawals on April 1, 2026. Its April 16 assessment put stolen assets at $295.7 million, including about $159.3 million in JLP and about $71.42 million in USDC. In a June 4 update, Drift said Mandiant had attributed the attack to North Korean group UNC6862. The platform remained under reconstruction, while partners including Tether planned to provide up to $147.5 million in recovery support.
All Coverage
4 original reportsThe Backstory
The history behind this eventSolana-Based Drift Secures $148 Million From Tether and Partners, Plans USDT-Based Relaunch
Drift is a major perpetual-contract protocol in the Solana ecosystem. It was previously hit by an attack linked to a North Korean hacking group, with initial losses estimated at about $270 million and the subsequent recovery plan putting the figure at $295 million. The incident harmed users’ funds and exposed risks in DeFi settlement and stablecoin partnership arrangements.
As of July 19, 2026, Drift had announced a user recovery and relaunch plan backed by $148 million from Tether, which led the financing, and partner institutions. The protocol will replace Circle’s USDC with Tether’s USDT as its core settlement asset and resume services using a redesigned architecture.
DeFi Protocol Carrot to Shut Down Permanently After $285 Million Drift Exploit
Carrot is a Solana-based DeFi yield protocol that allows users to deposit assets into strategies to earn returns. Its funds were heavily allocated to the Drift protocol, leaving Carrot with asset losses and rapidly dwindling liquidity after Drift was hacked for $285 million in early April. Carrot became the first protocol to announce its exit as a result of the incident.
The Carrot team said the protocol will shut down permanently on May 14 and instructed users to withdraw all remaining funds before the deadline. Carrot’s total value locked, or TVL, plunged 93% in one month amid the fallout from the Drift exploit. The closure also shows how a security breach at one major protocol can quickly spread through an interconnected DeFi ecosystem.
Solana-Based Drift Protocol Hacked for $220 Million
Drift Protocol is a major decentralized perpetual futures exchange in the Solana ecosystem, allowing users to deploy assets in trading, lending and vaults. The attack was not simply a smart-contract exploit but a prolonged infiltration targeting governance multisig controls and trust in personnel. More than half of the protocol's total value locked was affected, highlighting operational security risks in DeFi.
On April 1, 2026, the attackers seized control of Drift's multisig and transferred assets within 10 seconds. The loss estimate was raised from an initial range of $136 million to $220 million to $285 million, including $155.6 million in JLP, while DRIFT fell more than 30%. Drift said on April 5 that UNC4736, a North Korea-linked group, had posed as a quantitative trading firm since the fall of 2025, infiltrating the protocol for six months and using Durable Nonce to bypass its multisig.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →