Friday, April 3, 2026
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Alt Coins Solana

North Korean Hackers Attack Drift Protocol In $285 Million Heist

cryptonews100_tggfrn by cryptonews100_tggfrn
April 3, 2026
in Solana
0
North Korean Hackers Attack Drift Protocol In $285 Million Heist
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


Key takeaways

  • On April 1, 2026, attackers drained roughly USD 285 million in person belongings from Drift Protocol — the most important decentralized perpetual futures trade on Solana — in roughly 12 minutes, with most stolen funds bridged to Ethereum inside hours.
  • On-chain staging started on March 11, practically three weeks earlier than the April 1 execution — with attacker infrastructure, token manufacturing, and social engineering all working in parallel with cautious coordination.
  • The crucial vulnerability was not a wise contract bug however a mix of social engineering multisig signers into pre-signing hidden authorizations and a zero-timelock Safety Council migration that eradicated the protocol’s final line of protection.
  • The attacker manufactured a completely fictitious asset — CarbonVote Token — with a couple of thousand {dollars} in seeded liquidity and wash buying and selling, and Drift’s oracles handled it as legit collateral value a whole bunch of thousands and thousands of {dollars}.

On April 2, 2026, Drift Protocol confirmed that attackers drained roughly USD 285 million in person belongings on April 1, 2026. That is the most important DeFi hack of 2026 — and the second-largest exploit in Solana’s historical past, behind solely the USD 326 million Wormhole bridge hack in 2022. TRM’s preliminary investigation suggests the hack was possible perpetrated by North Korean hackers. 

What’s Drift, and the way precisely did this occur?

Drift is the most important decentralized perpetual futures trade on the Solana blockchain, permitting customers to commerce leveraged positions with out a centralized middleman. It held billions in person belongings, which made it a high-value, high-complexity goal.

The assault didn’t start on April 1. On-chain staging started weeks earlier, on March eleventh, with a single withdrawal of 10 ETH from Twister Money. These ETH started shifting hours later at round 12:00 AM GMT on March twelfth – or round 09:00 Pyongyang time – and shortly after funded the deployment of CarbonVote (CVT), the token used to govern Drift.

Between March 23 and March 30, the attacker created a number of “sturdy nonce” accounts — a legit Solana function that enables transactions to be pre-signed and executed later with out expiring. The attacker used social engineering to induce Drift Safety Council multisig signers into pre-signing transactions that appeared routine however carried hidden authorizations for crucial admin actions.

On March 27, Drift migrated its Safety Council to a brand new 2/5 threshold configuration with zero timelock — eliminating the delay that might have allowed detection and intervention. That migration created the exploitable hole.

In parallel, the attacker spent weeks manufacturing legitimacy for a faux token — CarbonVote Token (CVT) — minting 750 million items, seeding only a few thousand {dollars} in liquidity on Raydium, and utilizing wash buying and selling to construct a value historical past close to USD 1. Drift’s oracles picked up that synthetic sign and handled CVT as an actual asset.

On April 1, these pre-signed transactions had been deployed. The attacker listed CVT as legitimate collateral on Drift, raised withdrawal limits to excessive ranges, and deposited a whole bunch of thousands and thousands in CVT in opposition to that manufactured value. Then 31 withdrawal transactions executed in roughly 12 minutes — draining actual belongings together with USDC and JLP from the protocol.

Drift suspended deposits and withdrawals. The DRIFT token fell over 40%. Many of the stolen funds had been bridged inside hours to Ethereum.

The arrogance of the hackers was staggering. Every bridging transaction moved a whole bunch of 1000’s or, extra usually, thousands and thousands in USDC, far outstripping the velocity and aggressiveness of even the Bybit laundering of 2025.

‍

TRM Labs, which was the primary blockchain intelligence firm to cowl Solana, and has probably the most full protection of the blockchain right this moment, is actively monitoring the cross-chain funds motion and monitoring on-chain indicators associated to potential state actor involvement. Extra to come back as the image develops.

Regularly requested questions

1. What occurred to Drift Protocol?

On April 1, 2026, attackers drained roughly USD 285 million in person belongings from Drift Protocol, the most important decentralized perpetual futures trade on Solana, in roughly 12 minutes.

2. Why does TRM consider this was North Korea?

‍TRM’s preliminary investigation recognized a number of on-chain indicators per North Korean tradecraft, together with using Twister Money for preliminary staging, the deployment timing of the CarbonVote token at 09:30 Pyongyang time, the cross-chain bridging patterns, and the velocity and scale of post-hack laundering — all of which align intently with methods noticed in prior DPRK-attributed hacks together with the Bybit exploit of 2025.

3. How does this evaluate to different main crypto hacks?At USD 285 million, the Drift exploit is the most important DeFi hack of 2026 and the second-largest in Solana’s historical past, behind solely the USD 326 million Wormhole bridge hack in 2022. The post-hack laundering additionally exceeded the tempo of the Bybit exploit in 2025 in each velocity and transaction dimension, shifting thousands and thousands per transaction inside hours of the drain.

4. What ought to DeFi protocols do in another way in mild of this assault?‍

Three classes are instantly obvious. First, timelocks on governance and admin actions are a crucial safeguard — their removing, as occurred right here on March 27, eliminates the detection window that makes intervention potential. Second, oracle design requires defense-in-depth: protocols ought to require minimal liquidity thresholds, time-weighted value validation, and circuit breakers earlier than accepting any asset as collateral. Third, multisig hygiene issues — signers ought to have sturdy processes for independently verifying the total content material of any transaction earlier than signing, significantly these touching admin features.



Source link

Related articles

Solana price confirms bearish crossover following Drift exploit, will it crash?

Solana price confirms bearish crossover following Drift exploit, will it crash?

April 3, 2026
Latest crypto hack sees thieves make off with $280 million from Solana DeFi platform Drift

Latest crypto hack sees thieves make off with $280 million from Solana DeFi platform Drift

April 2, 2026
Tags: attackDriftHackersheistKoreanmillionNorthprotocol
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

Solana price confirms bearish crossover following Drift exploit, will it crash?

Solana price confirms bearish crossover following Drift exploit, will it crash?

by cryptonews100_tggfrn
April 3, 2026
0

Solana price fell almost 9% following a significant exploit on its Drift Protocol DeFi platform that drained almost $300 million...

Latest crypto hack sees thieves make off with $280 million from Solana DeFi platform Drift

Latest crypto hack sees thieves make off with $280 million from Solana DeFi platform Drift

by cryptonews100_tggfrn
April 2, 2026
0

On April Idiot’s day, the decentralized platform Drift noticed a whole lot of hundreds of thousands of {dollars} drained from...

Bitcoin Up or Down on April 2? Trading Odds & Predictions (Apr. 1, 2026)

Bitcoin Up or Down on April 2? Trading Odds & Predictions (Apr. 1, 2026)

by cryptonews100_tggfrn
April 2, 2026
0

This market will resolve to "Up" if the "Shut" worth for the Binance 1 minute candle for BTC/USDT Apr 1...

Trump reassures exiting war at Easter lunch – Solana, Dash, and River extend losses

Trump reassures exiting war at Easter lunch – Solana, Dash, and River extend losses

by cryptonews100_tggfrn
April 2, 2026
0

Bitcoin extends losses under $68,000 on Thursday, risking the 4% restoration from earlier this week.Donald Trump’s Easter lunch softens stress...

Solana Sets Monthly Record as Stablecoin Volume Hits $650B

Solana Sets Monthly Record as Stablecoin Volume Hits $650B

by cryptonews100_tggfrn
April 2, 2026
0

Regardless of Solana's record-breaking February, Ethereum nonetheless leads in cumulative stablecoin transaction quantity at round $52 trillion. The Solana...

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

X Product Lead: Automatic account lock and verification mechanism will be implemented for accounts publishing cryptocurrency content for the first time. | Blockchain 24/7 News – Blockchain Project Updates – Fintech News – Crypto Art News

April 3, 2026
US spot Ethereum ETFs see $71.17 million in net outflows…10x the prior day

US spot Ethereum ETFs see $71.17 million in net outflows…10x the prior day

April 3, 2026
Bitcoin Supply in Profit and Loss Closer to 2022 Bear Market Levels

Bitcoin Supply in Profit and Loss Closer to 2022 Bear Market Levels

April 3, 2026

Categories

  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Exchanges
  • Pokadot
  • Polygon
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

ADA (80) billion (56) Bitcoin (523) BTC (127) Buy (99) Cardano (148) ChainLink (105) crypto (539) Cryptocurrency (167) DOGE (53) Dogecoin (171) ETF (91) ETH (87) Ethereum (276) eyes (55) gains (60) Inu (114) key (63) launches (86) Liberty (58) march (62) market (197) million (65) News (270) PEPETO (56) Polkadot (90) POLYGON (74) prediction (162) Presale (63) price (437) rally (81) Recovery (66) Ripple (54) RWA (94) Shiba (123) Solana (148) Stablecoin (61) Sui (99) today (68) top (133) traders (54) TradingView (130) Trump (76) world (68) XRP (294)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • Pokadot
    • Polygon
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.