North Korea exploited Drift Protocol for $285M in what appears to be a state-sponsored DeFi heist.
Security & Exploits ·
Drift Protocol, Solana's largest decentralized perpetual futures exchange, lost $285 million on April 1 in what appears to be a state-sponsored attack. The exploit unfolded over 12 minutes through 31 rapid withdrawals, following a six-month operation that began in October 2025 when attackers posing as a quantitative trading firm cultivated relationships with Drift contributors at industry events. They then used social engineering to convince multisig signers to pre-approve hidden transactions via Solana's durable nonces feature, while simultaneously manufacturing a fake token called CarbonVote with minimal liquidity and wash trading to manipulate Drift's price oracles into treating it as legitimate collateral worth hundreds of millions of dollars.
Elliptic and TRM Labs both identified North Korean involvement, marking this as allegedly the 18th DPRK crypto attack of 2026. The exploit triggered significant market damage: DRIFT token fell over 40 percent, total value locked collapsed from approximately $550 million to under $250 million, and roughly a dozen Solana protocols dependent on Drift paused operations.
Questions remain about the full scope of the attack's aftermath and recovery efforts. The timeline of how Drift became aware of the exploit, the precise mechanics of how durable nonces were weaponized, and the effectiveness of any asset recovery measures are not yet detailed in available reporting.