#DriftProtocolHacked Drift Protocol's $285 Million Hack – How Did It Happen and What Should You Do?


Friends,
On April 1, 2026, a major attack occurred on the Solana blockchain. DeFi platform called Drift Protocol lost assets worth $285 2.85 billion dollars(.
This is the biggest DeFi hack of 2026 and the second-largest attack in Solana's history.
Let's understand in detail – what happened, how it happened, and what to do now.
What Happened? )What Happened?(
When did it happen? April 1, 2026 )April Fool’s Day( – Drift specifically confirmed that this is not a joke.
How much was lost? Approximately )assets worth 12.9 lakh ETH$285 .
What was stolen?
· JLP tokens – (million)
· USDC – $155 million+$51
· SOL – thousands of SOL
· cbBTC, wBTC, WETH, and some meme coins too
What happened to Drift Protocol?
· TVL (Total Value Locked) fell from $550 million to below million$300
· DRIFT token crashed over 50% – from $0.07 to $0.037
· Deposits and withdrawals were halted
How Did the Attack Happen? (The Attack Method – Step by Step)
This was not a simple smart contract hack. It was a highly sophisticated attack planned over weeks.
Step 1: Creating a Fake Token (CVT)
The hacker created a fake token named "CarbonVote Token" (CVT). 750 million units of this token were minted.
Step 2: Price Manipulation
The hacker added liquidity only on Raydium and used "wash trading" to make the CVT token's price appear around a certain level. Oracles believed this fake price to be real.
Step 3: Gaining Admin Access
Here’s the most critical part.
Drift's setup was already weak:
· A week earlier, Drift changed its multisig wallet
· New setup: 2/5 multisig $500 only 2 approvals needed$1
· No timelock (0-second delay)
· Out of 5 signers, only 1 was from the original team, the other 4 were new
The hacker compromised two signers – whether through private key leaks, social engineering, or internal collusion.
Step 4: Removing Withdrawal Limits
Once admin access was gained, the hacker increased withdrawal limits to extreme levels. No restrictions remained.
Step 5: Depositing Fake Collateral
The hacker deposited 750 million CVT tokens (fake value ~)million( into Drift as collateral.
Step 6: Draining Real Assets
Against this fake collateral, the hacker made 31 rapid withdrawals – within 12 minutes, they withdrew real assets like $750 USDC, SOL, JLP, etc.).
Step 7: Transferring Funds
The stolen funds were:
· First converted into USDC and SOL
· Then bridged on the Ethereum blockchain (using CCTP)
· Finally bought ETH – totaling around 129,000 ETH
Who Was Affected? (Who Was Affected?)
Protocol/Platform Status:
Jupiter Exchange is safe – JLP pool fully backed, platform unaffected
Meteora is safe – no interaction with Drift
Perena is safe – USD* products unaffected
PiggyBank_fi (exposure – covered by team funds
Ranger Finance RGUSD paused – over $900k exposure
Reflect Money USDC+/USDT+ paused – insurance in place
And yes – Unitas Protocol is also safe.
What Are the Big Questions? )The Big Questions$106k
Q1: Was it an external hack or an insider job? (監守自盜)
The community strongly suspects an "inside job." Why?
1. Timing suspicious – multisig was changed just a week before the attack
2. Too easy for an external hacker – gaining admin access shouldn’t have been so simple
3. Team’s reaction was abnormal – very calm response despite such a huge loss
4. Funds moved cleanly – converted to ETH, avoided risk of being frozen on CEXs
But remember: "Team member resigned a month ago" is just a Twitter rumor – no official confirmation.
Q2: Will the funds be recovered?
It's unlikely. The funds have already been converted into ETH and spread across multiple wallets. Circle (USDC issuer) has been blamed for not freezing the funds.
ZachXBT (famous on-chain detective) wrote:
"Millions in stolen USDC bridged while Circle sat on their hands."
Q3: Is North Korea involved?
Elliptic and some security firms suggest that North Korean hackers (Lazarus Group) might be behind this. If true, recovery of funds is nearly impossible.
Quick Summary Table
| Factor | Detail |
|---|---|
| Lost Amount | (2.85 billion)
| Date | April 1, 2026 |
| Blockchain | Solana $285 funds bridged to Ethereum( |
| Attack Type | Admin key compromise + Oracle manipulation |
| Main Targets | JLP, USDC, SOL, cbBTC |
| DRIFT Token Drop | Over 50% – from 0.07 to 0.037 |
| Current Status | Deposits/withdrawals paused, under investigation |
What Should You Do? )Action Plan for You(
If You Are a Drift User:
1. Revoke all approvals from Drift
2. Monitor official Drift channels for updates
3. Do not initiate any new transactions until all-clear is given
If You Are a General Crypto User:
1. Check your funds – on any protocol connected to Drift
2. Reduce leverage – the market is volatile
3. Keep an eye on the news – this case is a game-changer for DeFi security
If You Are a Trader:
· Expect short-term volatility in DRIFT token
· Negative sentiment in the Solana ecosystem – be cautious
· Do not "buy the dip" until the investigation is complete
Final Word )Final Word(
This hack is a warning sign for the DeFi industry:
"Permission security > Code security"
Meaning – no matter how strong your code is, if admin keys are compromised, everything is lost. Multisig, timelocks, and proper signing practices are not optional but mandatory.
The future of Drift Protocol is now uncertain. If funds are not recovered, bankruptcy, lawsuits, or shutdowns could happen.
Now It’s Your Turn
Do you think this was an external hack or an inside job?
And do you ever keep funds on a DeFi protocol?
Comment below
Like this
Share this
DRIFT2,69%
SOL1,32%
ETH-0,42%
View Original
post-image
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 13
  • 1
  • Share
Comment
Add a comment
Add a comment
MoonGirlvip
· 37m ago
To The Moon 🌕
Reply0
discoveryvip
· 9h ago
LFG 🔥
Reply0
discoveryvip
· 9h ago
To The Moon 🌕
Reply0
xxx40xxxvip
· 9h ago
2026 GOGOGO 👊
Reply0
xxx40xxxvip
· 9h ago
To The Moon 🌕
Reply0
CryptoDiscoveryvip
· 14h ago
LFG 🔥
Reply0
CryptoDiscoveryvip
· 14h ago
LFG 🔥
Reply0
Crypto_Buzz_with_Alexvip
· 14h ago
2026 GOGOGO 👊
Reply0
HighAmbitionvip
· 16h ago
thnxx for the update
Reply0
SheenCryptovip
· 18h ago
LFG 🔥
Reply0
View More
  • Pin