Mark RadarMARK RADAR
EN

Solana-Based Drift Protocol Hacked for $220 Million

24 reports · First detected 2026-04-02 · Last active 2026-04-30

Drift Protocol is a major decentralized perpetual futures exchange in the Solana ecosystem, allowing users to deploy assets in trading, lending and vaults. The attack was not simply a smart-contract exploit but a prolonged infiltration targeting governance multisig controls and trust in personnel. More than half of the protocol's total value locked was affected, highlighting operational security risks in DeFi.

On April 1, 2026, the attackers seized control of Drift's multisig and transferred assets within 10 seconds. The loss estimate was raised from an initial range of $136 million to $220 million to $285 million, including $155.6 million in JLP, while DRIFT fell more than 30%. Drift said on April 5 that UNC4736, a North Korea-linked group, had posed as a quantitative trading firm since the fall of 2025, infiltrating the protocol for six months and using Durable Nonce to bypass its multisig.

All Coverage

24 original reports

The Backstory

The history behind this event
Solana-Based Drift Secures $148 Million From Tether and Partners, Plans USDT-Based Relaunch2026-05-06 · 6 reports · similarity 0.83

Drift is a major perpetual-contract protocol in the Solana ecosystem. It was previously hit by an attack linked to a North Korean hacking group, with initial losses estimated at about $270 million and the subsequent recovery plan putting the figure at $295 million. The incident harmed users’ funds and exposed risks in DeFi settlement and stablecoin partnership arrangements.

As of July 19, 2026, Drift had announced a user recovery and relaunch plan backed by $148 million from Tether, which led the financing, and partner institutions. The protocol will replace Circle’s USDC with Tether’s USDT as its core settlement asset and resume services using a redesigned architecture.

DeFi Protocol Carrot to Shut Down Permanently After $285 Million Drift Exploit2026-05-01 · 1 reports · similarity 0.85

Carrot is a Solana-based DeFi yield protocol that allows users to deposit assets into strategies to earn returns. Its funds were heavily allocated to the Drift protocol, leaving Carrot with asset losses and rapidly dwindling liquidity after Drift was hacked for $285 million in early April. Carrot became the first protocol to announce its exit as a result of the incident.

The Carrot team said the protocol will shut down permanently on May 14 and instructed users to withdraw all remaining funds before the deadline. Carrot’s total value locked, or TVL, plunged 93% in one month amid the fallout from the Drift exploit. The closure also shows how a security breach at one major protocol can quickly spread through an interconnected DeFi ecosystem.

Drift Hack Victims Sue Circle Over Failure to Freeze $280 Million in Stolen USDC2026-04-28 · 2 reports · similarity 0.82

After Drift Protocol was hacked, about $280 million in assets was converted into USDC, prompting affected investors to file a class-action lawsuit against stablecoin issuer Circle. At the heart of the case is whether a centralized issuer has a duty to use its smart-contract powers to intercept proceeds from DeFi crimes, raising questions about the boundary between asset autonomy and victim protection.

As of July 20, 2026, the plaintiffs alleged that Circle knew the $280 million in USDC was suspected of being stolen but failed to freeze it during the critical six hours when the hacker moved the funds. Circle CEO Jeremy Allaire said the company freezes assets only at the direction of law enforcement, arguing that independently determining ownership could create legal and ethical risks.

At Least 12 Crypto Entities Attacked Since Drift Protocol Hack2026-04-17 · 1 reports · similarity 0.85

Decentralized finance protocol Drift Protocol was hacked on April 1, suffering losses of $280 million and highlighting how attackers can exploit DeFi smart contracts and market mechanisms. The significance extends beyond the damage to a single protocol, underscoring the risk of cascading security failures in the highly interconnected crypto ecosystem.

At least 12 crypto protocols and companies have been attacked since the Drift Protocol breach. Recent victims include Rhea Finance, which lost $7.6 million. Attackers continue to exploit vulnerabilities in DeFi protocols to manipulate trades, while the industry fears that advances in AI will lower barriers to such attacks and make them more frequent.

Solana Foundation Launches STRIDE and SIRN Security Programs After Drift Hack2026-04-08 · 5 reports · similarity 0.83

Drift Protocol, a major decentralized perpetual-futures trading platform in the Solana ecosystem, suffered estimated losses of about $270 million to $285 million on April 1, 2026, after a six-month social-engineering campaign targeting contributors and a device compromise. The incident did not involve a smart-contract vulnerability, but it highlighted the limits of relying on code audits alone to protect DeFi projects from risks involving personnel, keys and governance processes.

The Solana Foundation unveiled STRIDE and the Solana Incident Response Network, or SIRN, on April 6. Under STRIDE, Asymmetric Research assesses protocols across eight security areas. Protocols that pass the assessment and have more than $10 million in total value locked receive free, around-the-clock threat monitoring, while those with more than $100 million also receive formal verification. SIRN brings together security firms and researchers to respond to crises in real time.

Solana DeFi Platform Drift Investigates Suspected Attack, Urges Users to Halt Deposits2026-04-03 · 4 reports · similarity 0.85

Drift is a major decentralized perpetual futures and lending platform on Solana, where users deposit assets as trading collateral. The attacker did not exploit a software vulnerability. Instead, social engineering was used to secure approval from the Security Council multisig before Solana's “durable nonce” mechanism was abused to seize administrative control, highlighting the human signing and governance risks facing DeFi platforms.

Drift confirmed the attack and suspended deposits and withdrawals on April 1, 2026. Its April 16 assessment put stolen assets at $295.7 million, including about $159.3 million in JLP and about $71.42 million in USDC. In a June 4 update, Drift said Mandiant had attributed the attack to North Korean group UNC6862. The platform remained under reconstruction, while partners including Tether planned to provide up to $147.5 million in recovery support.

Solv Protocol Loses $2.7 Million in Exploit, Offers 10% Bounty for Return of Funds2026-03-06 · 1 reports · similarity 0.83

Solv Protocol is a Bitcoin-focused decentralized finance platform that allows users to convert BTC into SolvBTC for use in lending, staking and yield strategies. The vulnerability was confined to a single Bitcoin Reserve Offering (BRO) vault, but it nonetheless highlighted how flaws in smart-contract minting logic can directly erode on-chain assets and user trust.

On March 5, 2026, the attacker exploited a flaw in the BRO vault contract 22 times, converting improperly minted tokens into 38.0474 SolvBTC, worth about $2.7 million at the time. Solv Protocol has patched the vulnerability and is investigating with Hypernative, SlowMist and CertiK. The protocol said it would cover the loss and offered a 10% white-hat bounty if the attacker returned the remaining funds.

Solana Platform Step Finance Shuts Down After $27 Million Hack2026-02-24 · 1 reports · similarity 0.81

Step Finance is a DeFi portfolio aggregator in the Solana ecosystem that helps users track and manage on-chain assets. It also operates NFT analytics platform SolanaFloor and lending protocol Remora Markets. The shutdown shows how major cybersecurity losses can further erode Web3 teams’ ability to secure funding and sustain operations.

Step Finance said it was hacked in January 2026, with about $27 million in assets stolen. After failing to secure additional financing, it announced an immediate halt to all operations. The closure covers Step Finance, SolanaFloor and Remora Markets. The company is conducting a buyback for tokenholders but has not announced a completion timetable.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)