The fastest part of the Drift Protocol heist was not the attack. It was the withdrawal.
By the time transactions began emptying vaults on April 1, 2026, the operators behind the campaign had already spent roughly six months earning access, three weeks manufacturing a fake market, and days preserving signatures for later use. Investigators agree that the decisive opening took about 12 minutes, although they differ on whether all 31 withdrawals fit inside that window or continued through a roughly 2.5-hour sequence. The preparation made those first minutes possible.
The headline loss is usually $285 million; Drift's later asset ledger values the stolen tokens at $295.7 million. Understanding the heist means separating early estimates, later accounting, verified onchain actions, and allegations about the response.
What we can actually verify
This table is the short answer. It reconciles the numbers that otherwise make different accounts look like different attacks.
| Claim | Best-supported account | Why the distinction matters |
|---|---|---|
| Campaign duration | Relationship-building began in fall 2025; execution was April 1, 2026 | The six-month operation targeted people and process before it targeted protocol state |
| CVT preparation | CarbonVote Token was created around March 12 and traded for roughly three weeks | This was a staged collateral market, not a token invented during the drain |
| CVT quantities | About 750M minted, roughly 600M attacker-controlled, and 500M deposited | The sometimes-repeated 7.85M deposit is not supported by the detailed analyses |
| Apparent collateral | 500M CVT × an oracle price near $1 = roughly $500M | The protocol calculated correctly from inputs the attacker had made false |
| Withdrawal safeguards | Circuit breakers were raised by 20× or more across key markets | Available forensic accounts do not substantiate a $500 trillion limit |
| Withdrawal phase | Range places 31 withdrawals in about 12 minutes; Hypernative says the first 12 minutes extracted roughly $17.5M within a roughly 2.5-hour sequence | “12 minutes” describes the decisive opening, but the public reconstructions disagree on its exact boundary |
| Loss | $285–286M in early forensic estimates; $295,706,374.93 in Drift's later 19-asset ledger | Token prices and accounting cutoffs change the dollar total; $285M remains the recognizable incident estimate |
| Fund movement | Assets were swapped and moved through multiple venues and bridges | A class-action complaint alleges roughly $230M crossed Circle CCTP; it was not the only route |
| Response window | Public accounts describe roughly six to eight hours for the disputed CCTP movement | The available sources do not support the TODO claim of an 18-plus-hour freeze delay |
| Attribution | Early analysis assessed a DPRK link; Drift later said Mandiant attributed UNC6862 | “DPRK-linked” is supportable. Treating every DPRK operation as simply “Lazarus Group” loses important confidence and group distinctions |
The figures come from Chainalysis, Hypernative, Range, and Drift's later accounting.
The complete chain is easier to see as four clocks running at once:
| Clock | What happened | Control that failed |
|---|---|---|
| Fall 2025 to March 2026 | A purported quantitative trading firm built relationships, supplied detailed strategy material, committed more than $1M, and met contributors in person | Partner due diligence did not isolate relationship trust from signing-device trust |
| March 12 to April 1 | Attackers minted CVT, seeded shallow Raydium liquidity, and wash-traded it near $1 | Market history and an oracle price could look credible without proving economic depth |
| March 23 to March 30 | Four durable nonce accounts were created; signers approved nonce-bound transactions; Drift migrated to a 2-of-5 council with a zero-second timelock | Signatures remained executable later, while the new council had no review window |
| April 1 from about 16:05 UTC | Pre-signed transactions transferred admin control, CVT became collateral, safeguards were relaxed, 500M CVT was deposited, and the withdrawal sequence began | Valid privileged actions could change several safety boundaries and extract assets in one sequence |
Six months to obtain two valid signatures
The attackers reportedly presented as a real trading organization, not a generic phishing campaign. Range's synthesis says the group supplied credible documentation, deposited more than $1 million into an ecosystem vault, joined working sessions, and met contributors at conferences. That history made a stranger look like a partner.
Two delivery paths turned trust into access. One contributor cloned a repository with a weaponized VS Code tasks.json configuration; another downloaded a beta wallet through Apple TestFlight. The target was the environment where privileged approvals happened.
Durable nonces made the timing gap exploitable. A normal Solana transaction uses a recent blockhash and expires quickly. A durable transaction instead uses a value held in a nonce account and can be signed offline for later submission until that nonce advances. That is a legitimate feature for offline co-signing and delayed execution, as the Solana durable-nonce documentation demonstrates.
In Drift's case, the feature separated signing from danger. Four nonce accounts appeared between March 23 and March 30, and at least two council members reportedly signed nonce-bound transactions. The valid signatures persisted beyond the interface in which they were obtained.
The final accelerant was governance configuration. On March 27, a planned council migration produced a new 2-of-5 multisig with a zero-second timelock. Two approvals were enough, and there was no mandatory pause for another person or monitoring system to inspect what those approvals would do. On April 1, two pre-signed transactions submitted four Solana slots apart created, approved, and executed the transfer of administrative control.
How CVT converted fabricated price into real collateral
In parallel, the attackers prepared the thing that admin control would monetize. They minted approximately 750 million CVT, controlled about 600 million, provided a small amount of Raydium liquidity, and wash-traded the token around $1. A price history appeared where no meaningful market existed.
After taking administrative control, the attackers created a CVT spot market, configured it as collateral, loosened maintenance requirements, and raised withdrawal circuit breakers by at least 20 times across markets including USDC, wETH, dSOL, JLP, and cbBTC. They then deposited 500 million CVT.
The arithmetic was simple:
500,000,000 CVT × ~$1 oracle price = ~$500,000,000 apparent collateral
The failure was not multiplication. It was allowing one privileged path to decide that a shallow, recently manufactured market was worth $1, that its token could secure borrowing, and that the limits protecting real vault assets should rise at the same time. As Hypernative put it, the risk engine was enforcing the state it had been given. Once the attacker controlled those inputs, internally consistent accounting amplified the lie.
What left in 31 withdrawals
The early $285 million estimate is useful for naming the event. Drift's April 16 update provides the more complete ledger below. Its token-by-token values total $295,706,374.93.
| Asset | Value at Drift's accounting point |
|---|---|
| JLP | $159,329,898.68 |
| USDC | $71,415,648.65 |
| cbBTC | $11,321,165.24 |
| SOL | $10,426,959.98 |
| USDT | $5,648,410.13 |
| USDS | $5,254,126.13 |
| WETH | $4,684,896.11 |
| dSOL | $4,466,805.96 |
| WBTC | $4,359,399.64 |
| Fartcoin | $4,145,112.56 |
| jitoSOL | $3,598,696.98 |
| syrupUSDC | $3,318,311.45 |
| INF | $2,496,178.85 |
| mSOL | $1,989,219.36 |
| bSOL | $1,015,762.26 |
| EURC | $678,093.68 |
| zBTC | $591,147.51 |
| USDY | $536,721.64 |
| JUP | $429,820.12 |
| Total | $295,706,374.93 |
The largest first withdrawal cited by Range was 41.72 million JLP, then worth roughly $155 million. Range places all 31 withdrawals from Delta Neutral, Super Staking, and stablecoin vaults within approximately 12 minutes. Hypernative instead describes about $17.5 million extracted in the first 12 minutes and the wider operation lasting roughly 2.5 hours. The common ground is more important than forcing false precision: admin takeover and the first extraction happened within minutes, while subsequent swaps, bridges, and conversions continued afterward.
The bridge story is not one clean line
After withdrawal, the attackers used venues including Jupiter, Raydium, Orca, and Meteora to consolidate assets, then used CCTP, Wormhole, and deBridge routes to reach Ethereum before converting much of the value to ETH. Elliptic traced the cross-chain movement and described a rapid move from Solana to Ethereum.
A later class-action complaint against Circle alleges roughly $230 million of USDC crossed CCTP and says bridging completed about eight hours after the exploit began; other reporting describes six hours. These disputed claims do not support an 18-hour delay. Multiple exit routes nevertheless shortened the intervention window.
DPRK-linked does not automatically mean “Lazarus”
Attribution also evolved. Elliptic identified onchain, laundering, and network indicators consistent with prior DPRK operations. TRM assessed North Korean involvement and later described Drift as one of two attacks responsible for 76% of crypto hack losses through April 2026. Drift initially reported a medium-to-high-confidence connection to actors associated with the 2024 Radiant Capital attack.
By June, Drift said an independent Mandiant investigation conclusively attributed the attack to UNC6862, a North Korean threat group. That is stronger than an early methodology match, but it still does not justify using “Lazarus Group” as a catch-all label. Attribution should preserve the group identifier and confidence the investigator actually reported.
Why a code audit could pass while governance failed
Drift's contracts did not need an unknown arithmetic or verification flaw. The attack used permissions the system recognized as valid. That makes it fundamentally different from the 2022 Wormhole incident, where a verification failure allowed an attacker to mint 120,000 unbacked wrapped ETH, then worth about $326 million. The Wormhole incident report describes a code-level failure in signature-account verification. Drift was a control-plane failure: authorized instructions moved the protocol into an unsafe but permitted state.
A smart-contract audit can find a function that calculates collateral incorrectly. It cannot make an intentionally powerful admin function safe merely because the function behaves as designed. If an admin can add collateral, choose its oracle, weaken its risk parameters, and remove withdrawal limits immediately, the audit question must expand from “does each function work?” to “what is the maximum loss a valid sequence of privileged calls can create before anyone can stop it?”
That is why admin rotation alone is not enough. New keys inside the same unbounded, zero-delay authority reproduce the same failure mode with different signers.
The control matrix after Drift
No single control guarantees safety against a patient state-backed campaign. Independent controls must interrupt different links.
| Attack link | Prerequisite | Preventive control | Detective control | Expected interruption point | Residual risk and tradeoff |
|---|---|---|---|---|---|
| Partner compromise reaches a signer | Work material and signing occur on connected general-purpose devices | Dedicated signing devices; separate partner-work environments | Endpoint and repository scanning | Before malicious tooling reaches an approval device | More devices and slower workflows add operator burden |
| A signer approves disguised content | Interface hides the full instruction effect | Out-of-band decoding on an independent display; human-readable policy checks | Alert on unusual programs, authorities, or nonce use | Before the second signature | Decoders and policy engines can have their own blind spots |
| A signature persists for later use | Durable nonce remains valid | Prohibit durable nonces for high-risk admin roles or require short-lived policy envelopes | Inventory nonce accounts and alert on creation | During staging, days before execution | Offline co-signing becomes less convenient |
| Council takeover executes instantly | Threshold is met with no delay | Nonzero timelock for authority, threshold, and member changes | Independent watcher with cancellation power | Between approval and execution | Emergency response becomes slower; narrow pause roles may need an exception |
| Fake token becomes collateral | Admin can list and configure an immature market | Liquidity-depth, market-age, independent-oracle, and concentration gates | Detect wash trading and shallow price support | Before CVT receives borrowing power | New legitimate markets launch more slowly |
| One change removes several guardrails | Admin authority is broad and limits are unbounded | Parameter-specific caps and staged changes; separate roles for listing and limits | Alert on correlated changes across markets | During malicious reconfiguration | More governance steps increase coordination cost |
| Vaults drain faster than humans react | Per-asset and global outflows can jump immediately | Rolling withdrawal rate limits and circuit breakers that admin cannot instantly raise | Real-time outflow and insolvency monitoring | After the first abnormal withdrawals, before systemic loss | Tight limits can block users during genuine volatility |
The most important property is independence. A timelock that the same compromised authority can remove is not a timelock. A withdrawal limit that the same transaction can raise is not a loss boundary. An alert delivered only to compromised devices is not a second line of defense.
Drift's announced relaunch plan reflects several of these lessons. The protocol said signers would use dedicated devices, verify transaction content outside the primary interface, enforce timelocks on critical actions, receive real-time alerts, and disable durable nonces. It also planned a community-governed multisig and independent reviews by Ottersec and Asymmetric. On recovery, Drift proposed up to $127.5 million from Tether and $20 million from other partners, alongside a revenue-linked pool and transferable recovery claims for affected users.
Those measures matter, but recovery financing does not erase the security debt. The durable lesson of the Drift heist is that privileged access must have a bounded blast radius even when every signature is valid. DeFi teams should be able to answer three questions before the next transaction is signed: what can this authority change, how long must the change wait, and how much value can leave before an independent control stops it?
If the honest answers are “everything,” “immediately,” and “the whole vault,” another audit is not the missing defense.
Sources
- Drift: Incident Recovery Update and asset ledger
- Drift: June recovery update and Mandiant attribution
- Chainalysis: How privileged access led to the Drift loss
- Elliptic: Drift exploit tracing and DPRK indicators
- TRM Labs: North Korean hackers attack Drift Protocol
- Hypernative: The Drift exploit and privileged limits
- Range: Signer compromise and technical execution timeline
- Solana: Durable and offline transaction signing
- Wormhole: 2022 incident report



