Drift Protocol $285M Hack Deep Dive: Fake Tokens, Durable Nonces, and the Perfect Storm of Governance Hijacking

Drift Protocol $285M Hack Deep Dive: Fake Tokens, Durable Nonces, and the Perfect Storm of Governance Hijacking

中文 EN

On April 1, 2026 -- April Fools' Day -- Drift Protocol, the largest decentralized perpetual futures exchange on Solana, suffered the year's biggest DeFi hack. In just 12 minutes, the attacker drained approximately 285millioninuserassets,causingTVLtoplummetfrom285 million in user assets, causing TVL to plummet from 550 million to under $24 million, while the DRIFT token price crashed over 40%.

This was not a simple smart contract vulnerability. It was a meticulously orchestrated compound attack spanning over three weeks, combining fake token creation, oracle manipulation, social engineering, and the abuse of Solana-native features. Blockchain security firms Elliptic and TRM Labs both noted that the attack methods were highly consistent with the past operations of North Korea's Lazarus Group.

This article provides a complete technical breakdown of the incident.


I. Attack Overview

Before diving into the details, let's establish the overall framework. This attack involved three major attack vectors, each interlocking with the others:

  1. Fake token creation and oracle manipulation: Creating CarbonVote Token (CVT), building a price history through wash trading, and making oracles treat it as a legitimate asset
  2. Durable nonce pre-signed attack: Exploiting Solana's durable nonce mechanism to obtain multisig members' authorization signatures in advance, separating the "moment of signing" from the "moment of execution" by over a week
  3. Governance hijacking: Using compromised admin keys to list CVT as legitimate collateral, raise withdrawal limits, and ultimately drain the vaults in bulk

Each component alone would have been insufficient to cause damage, but when chained together, they formed a nearly indefensible attack.


II. Pre-Deployment: Three Weeks of Meticulous Preparation

2.1 Funding Source and Token Creation (March 11 - March 23)

The on-chain groundwork began on March 11 -- with a 10 ETH withdrawal from Tornado Cash. These funds began moving on March 12 at 0:00 GMT (approximately 9:00 AM Pyongyang time) and were subsequently used to deploy CarbonVote Token (CVT).

The attacker's token creation process:

  • Minting: Minted 750 million CVT
  • Liquidity injection: Established a liquidity pool on Raydium with just a few thousand dollars
  • Wash trading: Repeatedly traded through multiple addresses to artificially create a price history near $1
  • Establishing legitimacy: Days of sustained trading volume led on-chain oracles to begin quoting prices, making CVT appear to be a "real" asset

The key insight of this phase: the attacker didn't need CVT to actually have value -- they only needed the oracles to believe it had value.

2.2 Durable Nonce Account Preparation (March 23)

On March 23, the attacker created four durable nonce accounts. Two were associated with legitimate members of the Drift Security Committee, while the other two were controlled by the attacker.

To understand the significance of this step, we need to first understand Solana's durable nonce mechanism.

Solana's Transaction Expiry Problem

Every transaction on Solana includes a recent blockhash -- essentially a timestamp proving the transaction was recently created. This blockhash expires after approximately 60 to 90 seconds. If the transaction isn't submitted to the network within this window, it becomes invalid. This is a security feature designed to prevent old transactions from being replayed.

Durable Nonce: A Legitimate Way to Bypass Expiry

Durable nonces override this security feature. They replace the expiring blockhash with a fixed nonce (one-time code) stored in a special on-chain account, making the transaction valid indefinitely -- until someone chooses to submit it.

This feature is entirely legitimate, designed to support offline signing, multisig workflows, and similar use cases. But the attacker weaponized it: by separating the moment of signing from the moment of execution by over a week, they created a gap where the context at signing time was completely different from the context at execution time.

2.3 Governance Migration: Removing the Last Line of Defense (March 27)

On March 27, Drift migrated its Security Committee to a new 2/5 threshold configuration -- and more critically, adopted a zero timelock.

Timelocks are a critical security mechanism in multisig governance: after an administrative action is approved, a waiting period is required before execution, giving the community and monitoring systems an opportunity to detect and intervene on suspicious operations. Drift's migration directly removed this safeguard.

With a 2/5 threshold configuration, the attacker only needed to control two signers to pass any proposal. And they had already secured this capability on March 23.

2.4 Pre-Signed Transactions (March 31)

The day before the attack, the attacker prepared all pre-signed transactions. These transactions remained valid through durable nonces, awaiting the right moment to trigger.

The multisig members most likely believed they were signing routine transactions. The nature of durable nonces meant that signers reviewing the transaction had no way to determine when or under what conditions the transaction would be executed.


III. D-Day: 12 Minutes of Precision Strike

3.1 Attack Trigger

On April 1, approximately one minute after Drift executed a legitimate insurance fund test withdrawal, the attacker submitted the pre-signed durable nonce transactions.

Two transactions, separated by only four slots on the Solana blockchain, accomplished:

  1. Establishing the malicious admin transfer and obtaining approval
  2. Approving and executing the transfer

Within minutes, the attacker had gained complete protocol-level control over Drift.

3.2 Vault Draining

With control secured, the attacker immediately executed the following operations:

  1. Listed CVT as a legitimate collateral market: Using Drift's initializeSpotMarket function, which allows administrators to directly specify oracle address and source parameters. Even for a token like CVT with no Pyth oracle feed, admin privileges were sufficient to list it with an arbitrary oracle source
  2. Raised withdrawal limits to extreme levels: Removing the safety guardrails that would normally restrict large capital outflows
  3. Deposited hundreds of millions of CVT as collateral: Based on manipulated oracle prices, this collateral appeared to be worth hundreds of millions of dollars
  4. Batch withdrawals: 31 withdrawal transactions were executed over approximately 12 minutes, draining real assets including USDC, JLP, and others

3.3 Fund Movement

The funds were rapidly consolidated and converted:

  • Stolen assets were first uniformly swapped to USDC and SOL
  • Some funds were bridged to Ethereum via Circle's Cross-Chain Transfer Protocol (CCTP)
  • On Ethereum, portions were converted to ETH
  • Some funds flowed through centralized exchanges
  • Funds were ultimately dispersed across multiple wallets, increasing tracking difficulty

The entire laundering pattern -- including the speed and scale of cross-chain bridging -- was highly consistent with the methods observed in the February 2025 $1.4 billion Bybit hack.


IV. Technical Root Cause Analysis

4.1 This Was Not a Smart Contract Vulnerability

It must be emphasized: this attack did not exploit any smart contract code vulnerability. This is the third major DeFi attack in recent months that involved no code vulnerabilities. The core of the attack was:

  • Social engineering (inducing multisig members to pre-sign transactions)
  • Systemic weaknesses in governance architecture
  • Weaponization of legitimate features (durable nonces)

4.2 Excessive Admin Key Privileges

Drift's admin keys had an excessively concentrated privilege "attack surface." A single compromised signer could:

  • Rewrite the entire protocol's risk parameters
  • Specify arbitrary oracle sources
  • List new collateral markets
  • Modify withdrawal limits
  • Disable safety protections

When all these privileges are concentrated in a single admin role, compromising that role is equivalent to compromising the entire protocol.

4.3 Oracle Design Fragility

Drift's initializeSpotMarket function allowed administrators to directly specify oracle address and source parameters, meaning:

  • No validation through decentralized oracles (such as Pyth) was required
  • Administrators could set arbitrary price sources for any token
  • No automated checks on liquidity depth or market maturity were performed for newly listed collateral

4.4 The Fatal Decision of Zero Timelock

From a security perspective, the March 27 governance migration was the most critical failure. Setting the timelock to zero meant:

  • Malicious operations could be executed instantly
  • The community had no detection window
  • Monitoring systems had no reaction time
  • Any administrative action immediately took effect once it passed the multisig threshold

This essentially downgraded the multisig from a "security gate" to a "rubber stamp."


V. Attribution Analysis: North Korea's Lazarus Group

Analyses by Elliptic and TRM Labs both point to a North Korean state-sponsored hacking organization. Key evidence includes:

  1. On-chain behavioral patterns: Fund activation timing (Pyongyang working hours), cross-chain bridging speed and scale, and money laundering pathways were all consistent with previously attributed DPRK operations
  2. Historical links: Attack methods were highly similar to the February 2025 $1.4 billion Bybit hack
  3. Statistics: If attribution is confirmed, this would be the 18th DPRK-linked operation tracked in 2026, with cumulative stolen funds exceeding $300 million this year

Notably, North Korean hacking groups are shifting their focus from "finding code vulnerabilities" to "finding human vulnerabilities." Social engineering and operational security failures are becoming the primary pathways for DeFi protocol fund theft.


VI. Aftermath

Immediate Response

  • Drift immediately paused all deposit and withdrawal functions
  • The team confirmed they were working with security partners and ecosystem participants on the investigation
  • A software patch was pushed on April 3
  • On April 5, co-founders held a live Q&A, acknowledging that many important details remain unknown

Compensation Status

As of April 5:

  • No comprehensive compensation plan has been announced
  • On April 6, Drift met with DeFi insurance providers to discuss potential compensation schemes
  • No recovery of stolen funds has been confirmed
  • Recovery efforts are extremely complex due to the cross-chain dispersion of funds

ZachXBT's Criticism of Circle

On-chain detective ZachXBT publicly criticized Circle's response time in handling USDC, arguing that if Circle had frozen the relevant USDC faster, some losses could have been prevented. This reignited the debate over what role stablecoin issuers should play during security incidents.


VII. DeFi Security Takeaways

7.1 Audit Admin Keys, Not Just Code

A CoinDesk opinion piece perfectly captured this lesson in its title: "Audit admin keys, not just code." Current DeFi security audits are overly focused on smart contract code itself while neglecting:

  • Admin key privilege boundaries
  • Multisig configuration security
  • Timelock mechanism presence and reasonableness
  • Governance migration risk assessment

7.2 Durable Nonces Are a Double-Edged Sword

Durable nonces are a legitimate Solana feature that provides convenience for offline signing and multisig workflows. However, this attack revealed systemic risks in their use within multisig governance:

  • Signers cannot control when the transaction is executed
  • Pre-signed transactions can be executed in entirely different contexts
  • Multisig members need stricter transaction review processes

7.3 The Importance of Defense in Depth

If any of the following defensive layers had been in place, this attack could have been prevented or slowed:

  • Timelocks: Providing a detection and response window for the community
  • Additional collateral listing reviews: Requiring new collateral to pass automated checks on liquidity depth, market maturity, and more
  • Hard withdrawal caps: Withdrawal limits that even administrators cannot breach within a short timeframe
  • Multi-source oracle verification: Requiring collateral to be price-verified by at least two independent oracle sources
  • Tiered admin authorization: High-risk operations (such as listing new collateral, modifying withdrawal limits) requiring higher approval thresholds

7.4 People Are the Largest Attack Surface

No matter how sophisticated the technology, ultimate operational authority still rests with people. DeFi protocols must address:

  • Operational security training for multisig members
  • Social engineering defense drills
  • Independent verification processes for signing requests
  • Maintaining vigilance toward transactions that "look routine"

VIII. Conclusion

The Drift Protocol $285 million hack is not a story about "buggy code." It is a story about trust, governance design, and human vulnerability.

The attacker spent three weeks laying the groundwork, manufactured a legitimate-looking token, exploited a Solana feature designed for convenience, induced multisig members to unwittingly sign authorizations, and then -- the moment the last safety measure was removed -- completed the harvest in 12 minutes.

For the entire DeFi industry, the lesson from this incident is clear: code audits are necessary but far from sufficient. Governance architecture, admin key privileges, timelock mechanisms, oracle design, operational security -- these "non-code" security layers deserve equally serious attention.

The next $285 million vulnerability may not be in the code -- it may be in your governance process.


References