Drift Protocol, a Solana-based decentralized trading platform, said attackers stole about $280 million to $285 million after a months-long intrusion culminated in the takeover of administrative control and the draining of protocol vaults in roughly 12 minutes. Drift’s preliminary findings said the operation abused Solana’s durable nonce feature and pre-signed transactions rather than a simple smart contract flaw, while investigators reported that the attackers staged activity weeks in advance, created a fake asset called CarbonVote Token (CVT), and manipulated its trading history so protocol oracles would accept it as collateral. The stolen assets were then swapped largely into USDC and SOL, bridged to Ethereum through Circle’s Cross-Chain Transfer Protocol, and moved onward through additional services and exchanges.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Drift Protocol announced it is rebranding to Velocity DEX as it rebuilds after the April 1 exploit. The planned relaunch includes a private beta, a leaner perpetuals-only USDT-settled platform, a new program with rotated keys, removal of the durable-nonce mechanism abused in the attack, and a recovery plan backed by protocol revenue, a $127.5 million Tether commitment, and up to $20 million from partners.
Attorney Ariel Givner said Drift Protocol could face civil negligence claims because the team allegedly failed to follow basic operational security practices, including isolating signing keys and properly vetting external contacts. The commentary framed the exploit as a warning about social engineering risks in crypto development.
In post-mortem and follow-on reporting, investigators attributed the campaign with medium-high confidence to UNC4736, also known as AppleJeus or Citrine Sleet, and said it was likely linked to North Korean threat actors. Drift also said the same actors were behind the October 2024 Radiant Capital hack.
In later public findings, Drift said the exploit was the result of months of deliberate preparation by the attackers. The update reinforced that the theft stemmed from a prolonged social-engineering and malware campaign rather than a single isolated technical flaw.
By April 2, Drift had publicly described the incident as a highly sophisticated exploit involving abuse of Solana's durable nonce feature and pre-signed transactions rather than a simple smart contract bug. The disclosure also intensified scrutiny of Circle over its failure to freeze moved USDC during the response window.
On-chain investigators said the attacker converted much of the stolen crypto into USDC and SOL, then bridged funds from Solana to Ethereum using Circle's Cross-Chain Transfer Protocol. The proceeds were subsequently moved through additional wallets and centralized exchanges.
After detecting the exploit, Drift suspended deposits and withdrawals or otherwise froze protocol functions, removed the compromised wallet from its multisig, and began coordinating with security firms, exchanges, bridges, and law enforcement. The DRIFT token reportedly fell more than 20% following the incident.
On April 1, 2026, attackers used Solana's durable nonce mechanism and pre-signed transactions to gain unauthorized Security Council administrative control and drain Drift vaults in about 12 minutes. Reports put the losses at approximately $280 million to $285 million.
Before the theft, the attackers created a fake asset called CarbonVote Token (CVT) and wash traded it to fabricate a price history. Investigators said Drift's oracle system then accepted the manipulated asset as legitimate collateral.
Over roughly the next six months, the attackers allegedly sent malicious links and malware that compromised developer machines. Drift later said this developer compromise enabled the later administrative takeover.
Drift said the operation began when attackers engaged team members at a major crypto conference in October 2025. The adversaries then spent months building trust with developers as part of a long-term infiltration campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcecointelegraph.com
Open sourcethecyberexpress.com
Open sourcecointelegraph.com
Open sourcecointelegraph.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.