Drift Protocol, a Solana-based decentralized exchange, lost roughly $270 million to $286 million after attackers seized its Security Council administrative powers and drained core vaults, prompting the platform to suspend deposits and withdrawals and warn users not to add funds. Drift later said the theft was not caused by a smart contract bug or leaked seed phrases, but by a sophisticated operation that abused Solana durable nonce transactions and pre-signed multisig approvals to execute malicious governance changes later. Investigators and Drift said the attackers removed withdrawal limits, introduced a fake collateral asset called CVT or CarbonVote Token, manipulated controls, and rapidly moved assets out of borrow/lend products, vault deposits, and trading funds, cutting the protocol’s total value locked from about $550 million to below $250 million and sending the DRIFT token sharply lower.
Subsequent post-mortems described the breach as the culmination of a months-long social-engineering campaign in which the threat actors posed as a legitimate quantitative trading firm, built trust through conferences, Telegram chats, integrations, and deposits, and likely compromised contributors through a malicious code repository and a trojanized TestFlight wallet app. Blockchain intelligence firms including Elliptic and TRM Labs said the laundering patterns, cross-chain bridging from Solana to Ethereum, use of Tornado Cash, and other indicators were consistent with North Korean tradecraft, while Drift linked the operation with medium confidence to UNC4736 / AppleJeus / Citrine Sleet. The fallout widened beyond Drift as critics questioned why more than $230 million in USDC moved through Circle’s CCTP bridge without being frozen, Solana launched new security initiatives, and Drift later secured recovery backing including up to $127.5 million from Tether as it worked with security firms, exchanges, bridges, and law enforcement to trace and recover funds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
On April 16, Tether announced a strategic collaboration with Drift to support recovery and relaunch efforts, contributing up to $127.5 million as part of a package worth up to $150 million.
On April 14, Gibbs Mura filed a class action on behalf of affected Drift investors alleging Circle failed to freeze about $230 million in stolen USDC moved after the exploit.
By April 10, Drift had published a fuller post-mortem describing a six-month campaign in which attackers used fake companies, in-person meetings, Telegram conversations, and likely malicious tooling to gain access before the theft.
On April 7, the Solana Foundation announced Stride and the Solana Incident Response Network to improve DeFi security reviews and crisis response in the wake of the Drift exploit.
On April 5, Drift said the exploit was the culmination of a roughly six-month social-engineering campaign and attributed it with medium confidence to UNC4736, also known as AppleJeus or Citrine Sleet.
On April 2, Drift said the theft stemmed from a rapid takeover of Security Council administrative powers using pre-signed transactions created on March 23 and executed on April 1, and stated the incident was not caused by a smart contract flaw or compromised seed phrases.
On April 2, Elliptic said the $285 million Drift exploit showed multiple indicators consistent with North Korean state-sponsored activity, citing laundering methods, on-chain behavior, and network-level signals.
After the theft on April 1, investigators said the attacker rapidly consolidated funds, swapped assets into USDC and ETH, and bridged large amounts from Solana to Ethereum using Wormhole and Circle's CCTP.
As the attack unfolded on April 1, Drift said it was experiencing an active cyberattack and suspended deposits and withdrawals while coordinating with security firms, bridges, exchanges, and later law enforcement.
On April 1, attackers used pre-signed durable nonce transactions to take Security Council administrative control, add a malicious asset, remove withdrawal limits, and steal roughly $270 million to $286 million from Drift.
Drift announced on April 1 that it was investigating unusual activity on the protocol and told users not to deposit funds while the investigation was underway.
On April 1, Drift’s main vault saw rapid outflows across more than 15 token types, with roughly $270 million moved to unlabeled addresses in activity the team flagged as abnormal.
On March 27, Drift migrated its Security Council to a zero-timelock 2-of-5 configuration. Later reporting said the attackers adapted to this change and used it as part of the exploit chain.
Drift said preparations for the operation began on March 23, including creation of durable nonce accounts and obtaining pre-signed approvals that would later be used to seize Security Council powers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
30 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcethedefiant.io
Open sourcerekt.news
Open sourcetherecord.media
Open sourcecoindesk.com
Open sourcetechcrunch.com
Open sourcetherecord.media
Open sourcethedefiant.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.