Drift opened claims and redemptions for its DFX recovery token following the April 1 exploit that produced approximately $299.5 million in verified user losses. The initial Recovery Pool holds roughly $3.11 million USDT, giving DFX an opening redemption value of about 0.0104 USDT per token—approximately 1.04% of eligible losses. Users can claim DFX through the wallet that controlled their Drift account at the loss snapshot, then hold, trade, or redeem it; claims close on January 1, 2028 UTC.
The recovery program is intended to receive future funding from a tiered share of Velocity’s net protocol revenue, any recovered stolen assets, and potential commitments from Tether and strategic partners. Tether had previously announced support for a $150 million Drift recovery plan and a stabilized relaunch, alongside Drift’s plans to expand USDT usage on Solana; however, the initial pool represents only a small fraction of the verified losses.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Drift opened claims and redemptions for DFX, a recovery token with a supply corresponding to verified losses from the exploit. Its Recovery Pool launched with roughly 3.11 million USDT, giving DFX an initial redemption value of about 0.0104 USDT per token, or approximately 1.04% of verified losses.
An exploit affecting Drift caused approximately 299.5 million USDT in verified user losses. The loss snapshot later used for recovery allocations was tied to wallets controlling Drift accounts on this date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcetether.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.