Drift Protocol, a Solana derivatives platform, lost $285M to unusual fund outflows on April 2, 2026, in what appears to be a significant exploit.
Security & Exploits ·
On April 2, 2026, Drift Protocol, a Solana-based derivatives and lending platform, suffered unusual fund outflows totaling approximately $280 million, which the project subsequently confirmed resulted from an attack. The protocol has since halted deposits and withdrawals while coordinating with security firms, cross-chain bridges, and trading platforms.
Drift had operated as an integrated derivatives, spot trading, and lending protocol since its 2021 launch. As of 2024, it reported over $350 million in total value locked, serving more than 175,000 traders and generating $20 billion in cumulative trading volume. The protocol's safeguards included oracle validity checks, price-deviation band validation, and circuit breakers designed to restrict actions if oracle prices became invalid or manipulated. However, the attack exploited the permission layer—gaining unauthorized access to the Security Council multisig through durable nonce accounts and sophisticated social engineering, allowing the attacker to rewrite risk parameters and execute asset transfers after circumventing the underlying rules.
Drift's investigation found no evidence of compromised seed phrases or bugs in its smart contracts, indicating the attacker obtained disguised transaction approvals prior to execution. The operation appears to have been staged over several weeks. The exact methods by which the attacker secured sufficient multisig approvals remain incompletely disclosed in available statements.