Mark RadarMARK RADAR
EN
Event File CRYPTO Solana

Solana Foundation Launches STRIDE and SIRN Security Programs After Drift Hack

5 reports · First detected 2026-04-07 · Last active 2026-04-07

Drift Protocol, a major decentralized perpetual-futures trading platform in the Solana ecosystem, suffered estimated losses of about $270 million to $285 million on April 1, 2026, after a six-month social-engineering campaign targeting contributors and a device compromise. The incident did not involve a smart-contract vulnerability, but it highlighted the limits of relying on code audits alone to protect DeFi projects from risks involving personnel, keys and governance processes.

The Solana Foundation unveiled STRIDE and the Solana Incident Response Network, or SIRN, on April 6. Under STRIDE, Asymmetric Research assesses protocols across eight security areas. Protocols that pass the assessment and have more than $10 million in total value locked receive free, around-the-clock threat monitoring, while those with more than $100 million also receive formal verification. SIRN brings together security firms and researchers to respond to crises in real time.

All Coverage

5 original reports

The Backstory

The history behind this event
Solana-Based Drift Protocol Hacked for $220 Million2026-04-30 · 24 reports · similarity 0.83

Drift Protocol is a major decentralized perpetual futures exchange in the Solana ecosystem, allowing users to deploy assets in trading, lending and vaults. The attack was not simply a smart-contract exploit but a prolonged infiltration targeting governance multisig controls and trust in personnel. More than half of the protocol's total value locked was affected, highlighting operational security risks in DeFi.

On April 1, 2026, the attackers seized control of Drift's multisig and transferred assets within 10 seconds. The loss estimate was raised from an initial range of $136 million to $220 million to $285 million, including $155.6 million in JLP, while DRIFT fell more than 30%. Drift said on April 5 that UNC4736, a North Korea-linked group, had posed as a quantitative trading firm since the fall of 2025, infiltrating the protocol for six months and using Durable Nonce to bypass its multisig.

Mark Radar|MARK RADAR