logo

The Drift Protocol Hack: How Privileged Access Led to a $285 Million Loss

ID: 8d02d121-2213-5b4e-a2b3-0cc29dc30146

STIX ID: report--8d02d121-2213-5b4e-a2b3-0cc29dc30146

Feed Name: Chainalysis Blog

Threat Score
92/100

Date Published: 2026-04-09

Date Updated: 2026-04-27

Author: Chainalysis Team

...
...

On 1 April 2026 Drift Protocol on Solana was compromised and approximately $285 million (over 50% TVL) was drained after attackers used months-long social engineering to obtain pre-signed 'durable nonce' admin transactions, then whitelisted and deposited a fake token (CVT) as collateral to withdraw real assets; on-chain signals point to likely DPRK-linked actors and the exploit caused cascading disruption across at least 20 other protocols. The report emphasizes the sophistication and operational coordination of the attack and recommends real-time, intent-based pre-execution controls to prevent similar incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.