By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Notification
yourcryptonewstoday yourcryptonewstoday
  • Home
  • News
    • Crypto Bubbles
    • Regulations
    • Metaverse
  • MarketCap
  • Altcoins
    • Solana
  • Crypto
    • Bitcoin
    • Ethereum
    • Cardano
  • Blockchain
  • Market
    • Nft
  • Mining
  • Exchange
  • Analysis
    • Evaluation
    • Multi Currency
Reading: How Did Drift, Solana’s Largest Perpetuals DEX, Get $280 Million Stolen?
Share
bitcoin
Bitcoin (BTC) $ 66,916.00
ethereum
Ethereum (ETH) $ 2,048.15
tether
Tether (USDT) $ 0.999813
bnb
BNB (BNB) $ 590.09
usd-coin
USDC (USDC) $ 1.00
xrp
XRP (XRP) $ 1.31
binance-usd
BUSD (BUSD) $ 0.997805
dogecoin
Dogecoin (DOGE) $ 0.090825
cardano
Cardano (ADA) $ 0.243505
solana
Solana (SOL) $ 80.09
polkadot
Polkadot (DOT) $ 1.24
tron
TRON (TRX) $ 0.317353
Your Crypto News TodayYour Crypto News Today
  • Home
  • News
  • MarketCap
  • Altcoins
  • Crypto
  • Blockchain
  • Market
  • Mining
  • Exchange
  • Analysis
Search
  • Home
  • News
    • Crypto Bubbles
    • Regulations
    • Metaverse
  • MarketCap
  • Altcoins
    • Solana
  • Crypto
    • Bitcoin
    • Ethereum
    • Cardano
  • Blockchain
  • Market
    • Nft
  • Mining
  • Exchange
  • Analysis
    • Evaluation
    • Multi Currency
© 2024 All Rights reserved | Protected by Your Cryptonews Today
Your Crypto News Today > News > How Did Drift, Solana’s Largest Perpetuals DEX, Get $280 Million Stolen?
News

How Did Drift, Solana’s Largest Perpetuals DEX, Get $280 Million Stolen?

April 4, 2026 8 Min Read
Share
How Did Drift, Solana's Largest Perpetuals DEX, Get $280 Million Stolen?

Table of Contents

Toggle
  • How did the assault happen?
  • The timeline of the assault
  • Which Drift operations are affected?
  • The voices of the ecosystem

The Drift Protocol staff on April 2 printed a autopsy evaluation of the hack that drained roughly $280 million from the protocol the day before today.

Based on the report, the assault didn’t exploit any flaw within the protocol code: it was a several-week operation that mixed a strategy of pre-signing transactions with deception of members of the platform’s governing physique.

The quantity up to date by the staff is USD 280 million, barely larger than the USD 270 million reported within the hours after the hack. All deposits within the lending, vaults and buying and selling features had been affected. The protocol stays frozen on the time of this writing.

Drift Protocol is the primary decentralized alternate (DEX) for perpetual futures in Solana and the assault suffered represents the most important exploit within the Solana ecosystem because the Wormhole bridge hack in 2022, as reported by CriptoNoticias.

How did the assault happen?

Based on Drift’s assertion, the attacker took benefit of a mechanism within the Solana community that enables pre-sign transactions and hold them legitimate indefinitely to execute them at any time sooner or later.

These pre-signed transactions are known as sturdy nonces and are a authentic device of the protocol, usually used to automate scheduled funds. On this case, the attacker used them to acquire the mandatory approvals upfront of the Drift Safety Council, the physique that manages the protocol’s administrative permissions, and execute them weeks later.

The Council operates below a 2 out of 5 multisig scheme: not less than two signatures out of a doable 5 are wanted to approve any administrative motion. With two signers compromised through sturdy nonces, the attacker had all the things he wanted to take management, with out the signers essentially realizing what they had been authorizing.

Earlier immediately, a malicious actor gained unauthorized entry to Drift Protocol by way of a novel assault involving sturdy nonces, leading to a speedy takeover of Drift’s Safety Council administrative powers.

This was a extremely refined operation that seems to have concerned…

— Drift (@DriftProtocol) April 2, 2026

The timeline of the assault

As defined by the Drift staff, the operation passed off in three levels over ten days:

On March 23, the attacker created 4 sturdy nonce accounts: two related to members of Drift’s multisig and two below his personal management. At the moment, not less than two of the 5 signatories of the Council had accepted transactions linked to these accounts with out realizing that they had been pre-authorizing actions to be executed later.

On March 27, Drift executed a deliberate migration of its Safety Council because of a member change. Three days later, on March 30, the attacker created a brand new sturdy nonce account related to an upgraded council member, thus reestablishing efficient entry to 2 of the 5 signatures of the brand new multisig.

On April 1 the execution part arrived. Drift first made a authentic take a look at transaction from his insurance coverage fund. A minute later, the attacker executed two pre-signed transactions: the primary created and accepted a malicious administrative switch; the second he executed. Inside minutes it took full management over the protocol’s administrative permissions, launched a malicious asset, eliminated all preset withdrawal limits, and drained the funds.

Based on the assertion, the staff doesn’t rule out that the signatories have been victims of social engineering or a deceptive presentation of the transactions they accepted, though this trigger will not be confirmed and the investigation continues.

Which Drift operations are affected?

Based on the assertion, customers with funds deposited within the protocol for loans, buying and selling or in Drift vaults are affected.

DSOL tokens that weren’t deposited on Drift weren’t affected, together with property staked on the platform’s personal validator. The property of the Insurance coverage Fund had been faraway from the protocol preventively.

The multisig was up to date to take away the compromised pockets. Drift claims to be coordinating with safety corporations, exchanges, bridges and authorities to trace and freeze the stolen property.

The voices of the ecosystem

The onchain researcher ZachXBT focused Circlethe issuing firm of USDC, for not having acted whereas massive volumes of that stablecoin had been transferred from Solana to Ethereum throughout the assault.

Based on ZachXBT, the motion of funds occurred for hours with out intervention (realizing that they’ve the power to freeze USDC tokens), through the CCTP cross-chain switch protocol created by Circle. He additionally famous that Circle’s monitoring of the funds’ vacation spot contained errors: the attacker’s SOLs weren’t despatched to Hyperliquid or Binance, however bridged from Solana to Ethereum through Chainflip.

Charles Guillemet, chief expertise officer at Ledger, a {hardware} pockets maker, stated the sample of the assault is just like final 12 months’s Bybit hack, attributed to actors linked to North Korea: a affected person and complicated operation that focused the human and operational layer, not the code.

Guillemet believed that the signatories probably believed they had been approving a authentic operation whereas unknowingly authorizing the emptying of the protocol.

The Ledger government additionally known as for elevating safety requirements within the trade, together with higher detection of compromised environments, hardware-backed key administration and clear visibility into what’s being signed.

Drift Protocol, one of many main perpetual DEXs on Solana, has been hacked for roughly $213M. This makes it the most important hack of 2026 to this point, and one of many largest ever on the Solana blockchain, proper behind the Wormhole Bridge exploit of 2022.

The complete particulars of the…

— Charles Guillemet (@P3b7_) April 2, 2026

Lastly, the staff at Jupiter, Solana’s largest decentralized alternate by quantity, clarified that their protocol has no publicity to Drift markets and that the JLP token is absolutely backed by the underlying property.

Drift’s assertion describes a meticulous operation. Weeks of preparation, entry restored after a safety migration and execution in lower than a minute. The staff continues to coordinate with safety corporations, exchanges and authorities to trace the funds, with no confirmed outcomes to this point.

You Might Also Like

How Ethereum Became The Settlement Layer For All Altcoins

Will Trump’s Executive Order Break Bitcoin’s Four-Year Market Cycle?

Institutions and Exchanges Now Control 30% of Bitcoin Supply

Ethereum Regains Strength With a $2,800 Rebound, Will BitMine’s $59M Bet Break the Downtrend?

ETH Price Might Crash to $3,500 and Here’s Why

TAGGED:Casas de Cambio (exchange)CryptocurrenciesHackerSolana (SOL)TechnologyThe latest
Share This Article
Facebook Twitter Copy Link
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

How Did Drift, Solana's Largest Perpetuals DEX, Get $280 Million Stolen?
How Did Drift, Solana’s Largest Perpetuals DEX, Get $280 Million Stolen?
AvaCloud Ushers in New Era of Blockchain Privacy with Acquisition of EtraPay and Launch of Privacy Suite
AvaCloud Ushers in New Era of Blockchain Privacy with Acquisition of EtraPay and Launch of Privacy Suite
TRON's Justin Sun Debunks Binance Listing Rumors
TRON’s Justin Sun Debunks Binance Listing Rumors
Universal Health Token Debuts ‘PILLARS OF HEALTH’ NFT Collection
Universal Health Token Debuts ‘PILLARS OF HEALTH’ NFT Collection
Paragon Launches Flagship Loot-Box NFTs, Sell Out in Seconds
Paragon Launches Flagship Loot-Box NFTs, Sell Out in Seconds
Are NFTs Making a Return to Auction Houses?
Are NFTs Making a Return to Auction Houses?

You Might Also Like

Solana and BNB Behind Blockchain’s Biggest Week Yet — Everything to Know
Blockchain

Solana and BNB Behind Blockchain’s Biggest Week Yet — Everything to Know

July 16, 2025
Privacy-focused layer 2s will transform Ethereum’s enterprise future
Ethereum

Privacy-focused layer 2s will transform Ethereum’s enterprise future

February 10, 2025
La CNMV aclaró que no son el ente que regula a los exchanges de bitcoin. Fuente: Diario Información.
Regulations

will not be protected with MiCA

December 28, 2024
image
Altcoins

Validator Publishes U.S. GDP Data on XRP Ledger, Explains Why the Government Did Not Pick XRP

September 2, 2025
yourcryptonewstoday yourcryptonewstoday
yourcryptonewstoday yourcryptonewstoday

"In the fast-paced world of digital finance, staying informed is essential, and we’re here to help you navigate the evolving landscape of crypto currencies, blockchain, & digital assets."

Editor Choice

Coinbase Issues $1,200,000,000,000 Prediction for Stablecoin Market
Ethereum Breaks $4,000 — Analysts Say $10K Could Be Next as Institutions Pile In
Bitcoin’s Computing Power May Hit a Major Milestone Long Before Next Halving

Subscribe

* indicates required
/* real people should not fill this in and expect good things - do not remove this or risk form bot signups */

Intuit Mailchimp

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Linkedin Facebook
  • About Us
  • Contact Us
  • Disclaimer
  • Terms of Service
  • Privacy Policy
Reading: How Did Drift, Solana’s Largest Perpetuals DEX, Get $280 Million Stolen?
Share
Follow US
© 2025 All Rights reserved | Protected by Your Crypto News Today
Welcome Back!

Sign in to your account

Lost your password?