On April Fool’s Day, there was nothing funny happening on the Solana blockchain. In a meticulously engineered attack weeks in the making, suspected North Korean state-sponsored hackers drained approximately $285 million from Drift Protocol, the largest decentralized perpetual futures exchange on Solana — and the largest DeFi exploit of 2026 so far.
The attack did not rely on a software bug. It relied on patience, deception, and a fake token worth a few thousand dollars.
What Is Drift Protocol?
Drift, founded by Cindy Leow and David Lu in 2021, provides perpetual futures and other trading products to its users. It is a DeFi trading platform built on the Solana blockchain that serves as a non-custodial exchange, giving users full control of their funds as they interact with on-chain markets. As of late 2024, the platform claimed to have 200,000 traders, supporting total trading volumes of more than $55 billion.
The Anatomy of the Attack
Weeks of Preparation
The attack did not begin on April 1. The timeline shows a carefully staged operation. On March 23, durable nonce accounts were set up, with at least 2 of 5 multisig signers unknowingly approving transactions, enabling delayed execution. On March 27, Drift migrated its Security Council. By March 30, new nonce activity suggests the attacker regained access to 2 of 5 signers in the updated multisig, maintaining control ahead of the exploit.
On-chain staging actually began as early as March 11 with a Tornado Cash withdrawal. Blockchain intelligence firm TRM Labs noted that the critical vulnerability was not a smart contract bug, but a combination of social engineering multisig signers into pre-signing hidden authorizations and a zero-timelock Security Council migration that eliminated the protocol’s last line of defense.
The Fake Token at the Center of It All
Twenty days before the attack, the hackers minted a worthless token called CarbonVote Token (CVT). The attacker manufactured an entirely fictitious asset with a few thousand dollars in seeded liquidity and wash trading, and Drift’s oracles treated it as legitimate collateral worth hundreds of millions of dollars. Notably, the CarbonVote Token was deployed at 09:30 Pyongyang time — a detail investigators cite as one of several indicators linking the attack to North Korea.
Execution: 12 Minutes to Drain $285 Million
On April 1, the attack entered its execution phase. It began with a legitimate test withdrawal by Drift. About a minute later, the attacker used pre-signed durable nonce transactions to take control, creating, approving, and executing a malicious admin transfer, enabling the takeover.
Twenty-five seconds before the draining began, the hackers used the compromised admin key to simultaneously create a fake collateral market for CVT and disable Drift’s circuit breaker safety systems — the mechanisms designed to block withdrawals if too many assets are drained too quickly — by raising their threshold to 500 trillion. On April 1, they used compromised admin keys to list the token on Drift, post it as collateral, and drain real assets in 31 transactions over roughly 12 minutes.
Attackers targeted key vaults, stealing assets including $155 million in JLP tokens and other cryptocurrencies. Drift’s total value locked (TVL) dropped from $550 million to under $250 million.
At $285 million, this is the largest DeFi hack of 2026 and the second-largest exploit in Solana’s history, behind only the $326 million Wormhole bridge hack in 2022.
The Laundering Operation
Once the funds were stolen, the laundering operation kicked off at industrial scale. Stolen assets were routed through 27 “getaway” wallets, then scattered across more than 57,000 addresses using automated bots making roughly 590 transactions per minute. Stolen funds were quickly swapped to USDC, then moved to Ethereum and converted to ETH.
TRM Labs noted that the post-hack laundering exceeded the pace of the Bybit exploit in 2025 in both speed and transaction size. More than 860,000 transactions were recorded within 34 hours of the theft.
North Korea in the Frame
Blockchain intelligence firms Elliptic and TRM Labs both attributed the attack to North Korean state-sponsored actors with high confidence. Their findings are based on multiple on-chain indicators consistent with DPRK tradecraft, including Tornado Cash usage, CarbonVote deployment timing (09:30 Pyongyang time), cross-chain bridging patterns, and rapid large-scale laundering — all consistent with the Bybit hack.
This also included the cross-chain bridging patterns and the speed and scale of post-hack laundering that are consistent with hacks previously attributed to North Korean threat actors, including the massive Bybit exploit of 2025.
If confirmed, this incident would represent the eighteenth DPRK-linked operation Elliptic has tracked in 2026, with over $300 million stolen to date.
Ledger CTO Charles Guillemet drew parallels to the $1.4 billion Bybit hack, also attributed to North Korean actors, assessing that attackers likely compromised multisig signer machines through long-term infiltration.
A Systemic and Growing Threat
The Drift hack is not an isolated incident — it is the latest chapter in a sustained and escalating campaign. A Chainalysis report revealed DPRK hackers stole a record $2 billion in crypto in 2025, including the $1.4 billion Bybit breach, representing a 51% increase from the previous year.
The U.S. Treasury Department confirmed that North Korea uses stolen cryptocurrency assets to fund its weapons of mass destruction programs.
Elliptic warned that the DPRK’s cryptoasset theft operation is not a series of isolated incidents — it is a sustained, well-resourced campaign that is growing in scale and sophistication. The evolution of DPRK social engineering techniques, combined with the increasing availability of AI to refine these methods, means the threat extends well beyond exchanges.
The Aftermath
Drift Protocol is now working with security firms, cryptocurrency exchanges, and law enforcement authorities to trace and freeze the stolen funds. Drift sent on-chain messages on April 3 to four wallets holding the stolen ETH, urging the holders to open a dialogue.
Drift Protocol’s token price plummeted more than 40% to roughly $0.06 following the hack. All protocol functions remain essentially frozen as the investigation continues.
Trail of Bits audited Drift in 2022, and ClawSecure audited it in February 2026. Neither review identified the governance weaknesses that made the attack possible. The CVT market introduction and the zero-timelock Security Council migration fell outside the scope of code-focused audits. The attacker did not find a bug — they manufactured a crisis from the ground up, exploiting human trust, governance design gaps, and the irreversibility of blockchain transactions.
A few thousand dollars in a fake token. Twenty days of patience. Twelve minutes of execution. $285 million gone.
Securing your system against unknown active content is achievable by blocking malicious files and compromised data before execution. By integrating FileDNA into your security stack, you add a specialized layer that proactively neutralizes file-based threats with reliability and precision.