Skip to main content

Inside the $285M Drift Protocol Heist: Six Months of Trust, 12 Minutes to Start the Drain

13 min readDora NodaDora Noda
Share
On this page

The fastest part of the Drift Protocol heist was not the attack. It was the withdrawal.

By the time transactions began emptying vaults on April 1, 2026, the operators behind the campaign had already spent roughly six months earning access, three weeks manufacturing a fake market, and days preserving signatures for later use. Investigators agree that the decisive opening took about 12 minutes, although they differ on whether all 31 withdrawals fit inside that window or continued through a roughly 2.5-hour sequence. The preparation made those first minutes possible.

The headline loss is usually $285 million; Drift's later asset ledger values the stolen tokens at $295.7 million. Understanding the heist means separating early estimates, later accounting, verified onchain actions, and allegations about the response.

What we can actually verify

This table is the short answer. It reconciles the numbers that otherwise make different accounts look like different attacks.

ClaimBest-supported accountWhy the distinction matters
Campaign durationRelationship-building began in fall 2025; execution was April 1, 2026The six-month operation targeted people and process before it targeted protocol state
CVT preparationCarbonVote Token was created around March 12 and traded for roughly three weeksThis was a staged collateral market, not a token invented during the drain
CVT quantitiesAbout 750M minted, roughly 600M attacker-controlled, and 500M depositedThe sometimes-repeated 7.85M deposit is not supported by the detailed analyses
Apparent collateral500M CVT × an oracle price near $1 = roughly $500MThe protocol calculated correctly from inputs the attacker had made false
Withdrawal safeguardsCircuit breakers were raised by 20× or more across key marketsAvailable forensic accounts do not substantiate a $500 trillion limit
Withdrawal phaseRange places 31 withdrawals in about 12 minutes; Hypernative says the first 12 minutes extracted roughly $17.5M within a roughly 2.5-hour sequence“12 minutes” describes the decisive opening, but the public reconstructions disagree on its exact boundary
Loss$285–286M in early forensic estimates; $295,706,374.93 in Drift's later 19-asset ledgerToken prices and accounting cutoffs change the dollar total; $285M remains the recognizable incident estimate
Fund movementAssets were swapped and moved through multiple venues and bridgesA class-action complaint alleges roughly $230M crossed Circle CCTP; it was not the only route
Response windowPublic accounts describe roughly six to eight hours for the disputed CCTP movementThe available sources do not support the TODO claim of an 18-plus-hour freeze delay
AttributionEarly analysis assessed a DPRK link; Drift later said Mandiant attributed UNC6862“DPRK-linked” is supportable. Treating every DPRK operation as simply “Lazarus Group” loses important confidence and group distinctions

The figures come from Chainalysis, Hypernative, Range, and Drift's later accounting.

The complete chain is easier to see as four clocks running at once:

ClockWhat happenedControl that failed
Fall 2025 to March 2026A purported quantitative trading firm built relationships, supplied detailed strategy material, committed more than $1M, and met contributors in personPartner due diligence did not isolate relationship trust from signing-device trust
March 12 to April 1Attackers minted CVT, seeded shallow Raydium liquidity, and wash-traded it near $1Market history and an oracle price could look credible without proving economic depth
March 23 to March 30Four durable nonce accounts were created; signers approved nonce-bound transactions; Drift migrated to a 2-of-5 council with a zero-second timelockSignatures remained executable later, while the new council had no review window
April 1 from about 16:05 UTCPre-signed transactions transferred admin control, CVT became collateral, safeguards were relaxed, 500M CVT was deposited, and the withdrawal sequence beganValid privileged actions could change several safety boundaries and extract assets in one sequence

Six months to obtain two valid signatures

The attackers reportedly presented as a real trading organization, not a generic phishing campaign. Range's synthesis says the group supplied credible documentation, deposited more than $1 million into an ecosystem vault, joined working sessions, and met contributors at conferences. That history made a stranger look like a partner.

Two delivery paths turned trust into access. One contributor cloned a repository with a weaponized VS Code tasks.json configuration; another downloaded a beta wallet through Apple TestFlight. The target was the environment where privileged approvals happened.

Durable nonces made the timing gap exploitable. A normal Solana transaction uses a recent blockhash and expires quickly. A durable transaction instead uses a value held in a nonce account and can be signed offline for later submission until that nonce advances. That is a legitimate feature for offline co-signing and delayed execution, as the Solana durable-nonce documentation demonstrates.

In Drift's case, the feature separated signing from danger. Four nonce accounts appeared between March 23 and March 30, and at least two council members reportedly signed nonce-bound transactions. The valid signatures persisted beyond the interface in which they were obtained.

The final accelerant was governance configuration. On March 27, a planned council migration produced a new 2-of-5 multisig with a zero-second timelock. Two approvals were enough, and there was no mandatory pause for another person or monitoring system to inspect what those approvals would do. On April 1, two pre-signed transactions submitted four Solana slots apart created, approved, and executed the transfer of administrative control.

How CVT converted fabricated price into real collateral

In parallel, the attackers prepared the thing that admin control would monetize. They minted approximately 750 million CVT, controlled about 600 million, provided a small amount of Raydium liquidity, and wash-traded the token around $1. A price history appeared where no meaningful market existed.

After taking administrative control, the attackers created a CVT spot market, configured it as collateral, loosened maintenance requirements, and raised withdrawal circuit breakers by at least 20 times across markets including USDC, wETH, dSOL, JLP, and cbBTC. They then deposited 500 million CVT.

The arithmetic was simple:

500,000,000 CVT × ~$1 oracle price = ~$500,000,000 apparent collateral

The failure was not multiplication. It was allowing one privileged path to decide that a shallow, recently manufactured market was worth $1, that its token could secure borrowing, and that the limits protecting real vault assets should rise at the same time. As Hypernative put it, the risk engine was enforcing the state it had been given. Once the attacker controlled those inputs, internally consistent accounting amplified the lie.

What left in 31 withdrawals

The early $285 million estimate is useful for naming the event. Drift's April 16 update provides the more complete ledger below. Its token-by-token values total $295,706,374.93.

AssetValue at Drift's accounting point
JLP$159,329,898.68
USDC$71,415,648.65
cbBTC$11,321,165.24
SOL$10,426,959.98
USDT$5,648,410.13
USDS$5,254,126.13
WETH$4,684,896.11
dSOL$4,466,805.96
WBTC$4,359,399.64
Fartcoin$4,145,112.56
jitoSOL$3,598,696.98
syrupUSDC$3,318,311.45
INF$2,496,178.85
mSOL$1,989,219.36
bSOL$1,015,762.26
EURC$678,093.68
zBTC$591,147.51
USDY$536,721.64
JUP$429,820.12
Total$295,706,374.93

The largest first withdrawal cited by Range was 41.72 million JLP, then worth roughly $155 million. Range places all 31 withdrawals from Delta Neutral, Super Staking, and stablecoin vaults within approximately 12 minutes. Hypernative instead describes about $17.5 million extracted in the first 12 minutes and the wider operation lasting roughly 2.5 hours. The common ground is more important than forcing false precision: admin takeover and the first extraction happened within minutes, while subsequent swaps, bridges, and conversions continued afterward.

The bridge story is not one clean line

After withdrawal, the attackers used venues including Jupiter, Raydium, Orca, and Meteora to consolidate assets, then used CCTP, Wormhole, and deBridge routes to reach Ethereum before converting much of the value to ETH. Elliptic traced the cross-chain movement and described a rapid move from Solana to Ethereum.

A later class-action complaint against Circle alleges roughly $230 million of USDC crossed CCTP and says bridging completed about eight hours after the exploit began; other reporting describes six hours. These disputed claims do not support an 18-hour delay. Multiple exit routes nevertheless shortened the intervention window.

DPRK-linked does not automatically mean “Lazarus”

Attribution also evolved. Elliptic identified onchain, laundering, and network indicators consistent with prior DPRK operations. TRM assessed North Korean involvement and later described Drift as one of two attacks responsible for 76% of crypto hack losses through April 2026. Drift initially reported a medium-to-high-confidence connection to actors associated with the 2024 Radiant Capital attack.

By June, Drift said an independent Mandiant investigation conclusively attributed the attack to UNC6862, a North Korean threat group. That is stronger than an early methodology match, but it still does not justify using “Lazarus Group” as a catch-all label. Attribution should preserve the group identifier and confidence the investigator actually reported.

Why a code audit could pass while governance failed

Drift's contracts did not need an unknown arithmetic or verification flaw. The attack used permissions the system recognized as valid. That makes it fundamentally different from the 2022 Wormhole incident, where a verification failure allowed an attacker to mint 120,000 unbacked wrapped ETH, then worth about $326 million. The Wormhole incident report describes a code-level failure in signature-account verification. Drift was a control-plane failure: authorized instructions moved the protocol into an unsafe but permitted state.

A smart-contract audit can find a function that calculates collateral incorrectly. It cannot make an intentionally powerful admin function safe merely because the function behaves as designed. If an admin can add collateral, choose its oracle, weaken its risk parameters, and remove withdrawal limits immediately, the audit question must expand from “does each function work?” to “what is the maximum loss a valid sequence of privileged calls can create before anyone can stop it?”

That is why admin rotation alone is not enough. New keys inside the same unbounded, zero-delay authority reproduce the same failure mode with different signers.

The control matrix after Drift

No single control guarantees safety against a patient state-backed campaign. Independent controls must interrupt different links.

Attack linkPrerequisitePreventive controlDetective controlExpected interruption pointResidual risk and tradeoff
Partner compromise reaches a signerWork material and signing occur on connected general-purpose devicesDedicated signing devices; separate partner-work environmentsEndpoint and repository scanningBefore malicious tooling reaches an approval deviceMore devices and slower workflows add operator burden
A signer approves disguised contentInterface hides the full instruction effectOut-of-band decoding on an independent display; human-readable policy checksAlert on unusual programs, authorities, or nonce useBefore the second signatureDecoders and policy engines can have their own blind spots
A signature persists for later useDurable nonce remains validProhibit durable nonces for high-risk admin roles or require short-lived policy envelopesInventory nonce accounts and alert on creationDuring staging, days before executionOffline co-signing becomes less convenient
Council takeover executes instantlyThreshold is met with no delayNonzero timelock for authority, threshold, and member changesIndependent watcher with cancellation powerBetween approval and executionEmergency response becomes slower; narrow pause roles may need an exception
Fake token becomes collateralAdmin can list and configure an immature marketLiquidity-depth, market-age, independent-oracle, and concentration gatesDetect wash trading and shallow price supportBefore CVT receives borrowing powerNew legitimate markets launch more slowly
One change removes several guardrailsAdmin authority is broad and limits are unboundedParameter-specific caps and staged changes; separate roles for listing and limitsAlert on correlated changes across marketsDuring malicious reconfigurationMore governance steps increase coordination cost
Vaults drain faster than humans reactPer-asset and global outflows can jump immediatelyRolling withdrawal rate limits and circuit breakers that admin cannot instantly raiseReal-time outflow and insolvency monitoringAfter the first abnormal withdrawals, before systemic lossTight limits can block users during genuine volatility

The most important property is independence. A timelock that the same compromised authority can remove is not a timelock. A withdrawal limit that the same transaction can raise is not a loss boundary. An alert delivered only to compromised devices is not a second line of defense.

Drift's announced relaunch plan reflects several of these lessons. The protocol said signers would use dedicated devices, verify transaction content outside the primary interface, enforce timelocks on critical actions, receive real-time alerts, and disable durable nonces. It also planned a community-governed multisig and independent reviews by Ottersec and Asymmetric. On recovery, Drift proposed up to $127.5 million from Tether and $20 million from other partners, alongside a revenue-linked pool and transferable recovery claims for affected users.

Those measures matter, but recovery financing does not erase the security debt. The durable lesson of the Drift heist is that privileged access must have a bounded blast radius even when every signature is valid. DeFi teams should be able to answer three questions before the next transaction is signed: what can this authority change, how long must the change wait, and how much value can leave before an independent control stops it?

If the honest answers are “everything,” “immediately,” and “the whole vault,” another audit is not the missing defense.

Sources

Related articles

Learn with a bex course

A short, practical course — from primitives to production — built from the bex docs and the corpus you just read.

Start course