Drift Protocol $285M Hack Deep Dive: Fake Tokens, Durable Nonces, and the Perfect Storm of Governance Hijacking
On April 1, 2026 -- April Fools' Day -- Drift Protocol, the largest decentralized perpetual futures exchange on Solana, suffered the year's biggest DeFi hack. In just 12 minutes, the attacker drained approximately 550 million to under $24 million, while the DRIFT token price crashed over 40%.
This was not a simple smart contract vulnerability. It was a meticulously orchestrated compound attack spanning over three weeks, combining fake token creation, oracle manipulation, social engineering, and the abuse of Solana-native features. Blockchain security firms Elliptic and TRM Labs both noted that the attack methods were highly consistent with the past operations of North Korea's Lazarus Group.
This article provides a complete technical breakdown of the incident.
I. Attack Overview
Before diving into the details, let's establish the overall framework. This attack involved three major attack vectors, each interlocking with the others:
- Fake token creation and oracle manipulation: Creating CarbonVote Token (CVT), building a price history through wash trading, and making oracles treat it as a legitimate asset
- Durable nonce pre-signed attack: Exploiting Solana's durable nonce mechanism to obtain multisig members' authorization signatures in advance, separating the "moment of signing" from the "moment of execution" by over a week
- Governance hijacking: Using compromised admin keys to list CVT as legitimate collateral, raise withdrawal limits, and ultimately drain the vaults in bulk
Each component alone would have been insufficient to cause damage, but when chained together, they formed a nearly indefensible attack.
II. Pre-Deployment: Three Weeks of Meticulous Preparation
2.1 Funding Source and Token Creation (March 11 - March 23)
The on-chain groundwork began on March 11 -- with a 10 ETH withdrawal from Tornado Cash. These funds began moving on March 12 at 0:00 GMT (approximately 9:00 AM Pyongyang time) and were subsequently used to deploy CarbonVote Token (CVT).
The attacker's token creation process:
- Minting: Minted 750 million CVT
- Liquidity injection: Established a liquidity pool on Raydium with just a few thousand dollars
- Wash trading: Repeatedly traded through multiple addresses to artificially create a price history near $1
- Establishing legitimacy: Days of sustained trading volume led on-chain oracles to begin quoting prices, making CVT appear to be a "real" asset
The key insight of this phase: the attacker didn't need CVT to actually have value -- they only needed the oracles to believe it had value.
2.2 Durable Nonce Account Preparation (March 23)
On March 23, the attacker created four durable nonce accounts. Two were associated with legitimate members of the Drift Security Committee, while the other two were controlled by the attacker.
To understand the significance of this step, we need to first understand Solana's durable nonce mechanism.
Solana's Transaction Expiry Problem
Every transaction on Solana includes a recent blockhash -- essentially a timestamp proving the transaction was recently created. This blockhash expires after approximately 60 to 90 seconds. If the transaction isn't submitted to the network within this window, it becomes invalid. This is a security feature designed to prevent old transactions from being replayed.
Durable Nonce: A Legitimate Way to Bypass Expiry
Durable nonces override this security feature. They replace the expiring blockhash with a fixed nonce (one-time code) stored in a special on-chain account, making the transaction valid indefinitely -- until someone chooses to submit it.
This feature is entirely legitimate, designed to support offline signing, multisig workflows, and similar use cases. But the attacker weaponized it: by separating the moment of signing from the moment of execution by over a week, they created a gap where the context at signing time was completely different from the context at execution time.
2.3 Governance Migration: Removing the Last Line of Defense (March 27)
On March 27, Drift migrated its Security Committee to a new 2/5 threshold configuration -- and more critically, adopted a zero timelock.
Timelocks are a critical security mechanism in multisig governance: after an administrative action is approved, a waiting period is required before execution, giving the community and monitoring systems an opportunity to detect and intervene on suspicious operations. Drift's migration directly removed this safeguard.
With a 2/5 threshold configuration, the attacker only needed to control two signers to pass any proposal. And they had already secured this capability on March 23.
2.4 Pre-Signed Transactions (March 31)
The day before the attack, the attacker prepared all pre-signed transactions. These transactions remained valid through durable nonces, awaiting the right moment to trigger.
The multisig members most likely believed they were signing routine transactions. The nature of durable nonces meant that signers reviewing the transaction had no way to determine when or under what conditions the transaction would be executed.
III. D-Day: 12 Minutes of Precision Strike
3.1 Attack Trigger
On April 1, approximately one minute after Drift executed a legitimate insurance fund test withdrawal, the attacker submitted the pre-signed durable nonce transactions.
Two transactions, separated by only four slots on the Solana blockchain, accomplished:
- Establishing the malicious admin transfer and obtaining approval
- Approving and executing the transfer
Within minutes, the attacker had gained complete protocol-level control over Drift.
3.2 Vault Draining
With control secured, the attacker immediately executed the following operations:
- Listed CVT as a legitimate collateral market: Using Drift's
initializeSpotMarketfunction, which allows administrators to directly specify oracle address and source parameters. Even for a token like CVT with no Pyth oracle feed, admin privileges were sufficient to list it with an arbitrary oracle source - Raised withdrawal limits to extreme levels: Removing the safety guardrails that would normally restrict large capital outflows
- Deposited hundreds of millions of CVT as collateral: Based on manipulated oracle prices, this collateral appeared to be worth hundreds of millions of dollars
- Batch withdrawals: 31 withdrawal transactions were executed over approximately 12 minutes, draining real assets including USDC, JLP, and others
3.3 Fund Movement
The funds were rapidly consolidated and converted:
- Stolen assets were first uniformly swapped to USDC and SOL
- Some funds were bridged to Ethereum via Circle's Cross-Chain Transfer Protocol (CCTP)
- On Ethereum, portions were converted to ETH
- Some funds flowed through centralized exchanges
- Funds were ultimately dispersed across multiple wallets, increasing tracking difficulty
The entire laundering pattern -- including the speed and scale of cross-chain bridging -- was highly consistent with the methods observed in the February 2025 $1.4 billion Bybit hack.
IV. Technical Root Cause Analysis
4.1 This Was Not a Smart Contract Vulnerability
It must be emphasized: this attack did not exploit any smart contract code vulnerability. This is the third major DeFi attack in recent months that involved no code vulnerabilities. The core of the attack was:
- Social engineering (inducing multisig members to pre-sign transactions)
- Systemic weaknesses in governance architecture
- Weaponization of legitimate features (durable nonces)
4.2 Excessive Admin Key Privileges
Drift's admin keys had an excessively concentrated privilege "attack surface." A single compromised signer could:
- Rewrite the entire protocol's risk parameters
- Specify arbitrary oracle sources
- List new collateral markets
- Modify withdrawal limits
- Disable safety protections
When all these privileges are concentrated in a single admin role, compromising that role is equivalent to compromising the entire protocol.
4.3 Oracle Design Fragility
Drift's initializeSpotMarket function allowed administrators to directly specify oracle address and source parameters, meaning:
- No validation through decentralized oracles (such as Pyth) was required
- Administrators could set arbitrary price sources for any token
- No automated checks on liquidity depth or market maturity were performed for newly listed collateral
4.4 The Fatal Decision of Zero Timelock
From a security perspective, the March 27 governance migration was the most critical failure. Setting the timelock to zero meant:
- Malicious operations could be executed instantly
- The community had no detection window
- Monitoring systems had no reaction time
- Any administrative action immediately took effect once it passed the multisig threshold
This essentially downgraded the multisig from a "security gate" to a "rubber stamp."
V. Attribution Analysis: North Korea's Lazarus Group
Analyses by Elliptic and TRM Labs both point to a North Korean state-sponsored hacking organization. Key evidence includes:
- On-chain behavioral patterns: Fund activation timing (Pyongyang working hours), cross-chain bridging speed and scale, and money laundering pathways were all consistent with previously attributed DPRK operations
- Historical links: Attack methods were highly similar to the February 2025 $1.4 billion Bybit hack
- Statistics: If attribution is confirmed, this would be the 18th DPRK-linked operation tracked in 2026, with cumulative stolen funds exceeding $300 million this year
Notably, North Korean hacking groups are shifting their focus from "finding code vulnerabilities" to "finding human vulnerabilities." Social engineering and operational security failures are becoming the primary pathways for DeFi protocol fund theft.
VI. Aftermath
Immediate Response
- Drift immediately paused all deposit and withdrawal functions
- The team confirmed they were working with security partners and ecosystem participants on the investigation
- A software patch was pushed on April 3
- On April 5, co-founders held a live Q&A, acknowledging that many important details remain unknown
Compensation Status
As of April 5:
- No comprehensive compensation plan has been announced
- On April 6, Drift met with DeFi insurance providers to discuss potential compensation schemes
- No recovery of stolen funds has been confirmed
- Recovery efforts are extremely complex due to the cross-chain dispersion of funds
ZachXBT's Criticism of Circle
On-chain detective ZachXBT publicly criticized Circle's response time in handling USDC, arguing that if Circle had frozen the relevant USDC faster, some losses could have been prevented. This reignited the debate over what role stablecoin issuers should play during security incidents.
VII. DeFi Security Takeaways
7.1 Audit Admin Keys, Not Just Code
A CoinDesk opinion piece perfectly captured this lesson in its title: "Audit admin keys, not just code." Current DeFi security audits are overly focused on smart contract code itself while neglecting:
- Admin key privilege boundaries
- Multisig configuration security
- Timelock mechanism presence and reasonableness
- Governance migration risk assessment
7.2 Durable Nonces Are a Double-Edged Sword
Durable nonces are a legitimate Solana feature that provides convenience for offline signing and multisig workflows. However, this attack revealed systemic risks in their use within multisig governance:
- Signers cannot control when the transaction is executed
- Pre-signed transactions can be executed in entirely different contexts
- Multisig members need stricter transaction review processes
7.3 The Importance of Defense in Depth
If any of the following defensive layers had been in place, this attack could have been prevented or slowed:
- Timelocks: Providing a detection and response window for the community
- Additional collateral listing reviews: Requiring new collateral to pass automated checks on liquidity depth, market maturity, and more
- Hard withdrawal caps: Withdrawal limits that even administrators cannot breach within a short timeframe
- Multi-source oracle verification: Requiring collateral to be price-verified by at least two independent oracle sources
- Tiered admin authorization: High-risk operations (such as listing new collateral, modifying withdrawal limits) requiring higher approval thresholds
7.4 People Are the Largest Attack Surface
No matter how sophisticated the technology, ultimate operational authority still rests with people. DeFi protocols must address:
- Operational security training for multisig members
- Social engineering defense drills
- Independent verification processes for signing requests
- Maintaining vigilance toward transactions that "look routine"
VIII. Conclusion
The Drift Protocol $285 million hack is not a story about "buggy code." It is a story about trust, governance design, and human vulnerability.
The attacker spent three weeks laying the groundwork, manufactured a legitimate-looking token, exploited a Solana feature designed for convenience, induced multisig members to unwittingly sign authorizations, and then -- the moment the last safety measure was removed -- completed the harvest in 12 minutes.
For the entire DeFi industry, the lesson from this incident is clear: code audits are necessary but far from sufficient. Governance architecture, admin key privileges, timelock mechanisms, oracle design, operational security -- these "non-code" security layers deserve equally serious attention.
The next $285 million vulnerability may not be in the code -- it may be in your governance process.
References
- Drift Protocol exploited for $286 million in suspected DPRK-linked attack -- Elliptic's on-chain analysis attributing the exploit to North Korean state-sponsored actors
- North Korean Hackers Attack Drift Protocol In USD 285 Million Heist -- TRM Labs' investigation into DPRK laundering methodologies and network-level indicators
- Elliptic flags $285 million Drift exploit as a likely North Korea-linked operation -- CoinDesk coverage of Elliptic's attribution findings
- How a Solana feature designed for convenience let an attacker drain $270 million from Drift -- CoinDesk technical breakdown of the durable nonce attack vector
- Drift says $270 million exploit was a six-month North Korean intelligence operation -- CoinDesk report on Drift's post-mortem revealing the six-month infiltration campaign
- Audit admin keys, not just code, expert says after $200 million Drift exploit -- CoinDesk opinion piece on admin key security featuring Chaos Labs founder Omer Goldberg
- Circle under fire after $285 million Drift hack over inaction to freeze stolen USDC -- CoinDesk report on ZachXBT's criticism of Circle's delayed USDC freeze response
- Drift Protocol Hit by $285M Exploit: Crypto's Biggest Hack of 2026 Unfolds on April Fool's Day -- CCN's comprehensive timeline of the attack and immediate aftermath
- $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation -- The Hacker News analysis of the social engineering campaign by UNC4736
- Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK -- The Hacker News technical coverage of the durable nonce exploitation
- Drift Protocol Suffers $285 Million Exploit After Admin Key Compromise and Oracle Manipulation -- Unchained Crypto's breakdown of the admin key compromise and oracle manipulation
- Circle Faces Backlash for Failing to Freeze Stolen USDC During $285 Million Drift Exploit -- Unchained Crypto's coverage of the Circle USDC freeze controversy
- Circle Had 6 Hours to Freeze Stolen Drift Funds -- It Did Nothing: ZachXBT -- CryptoTimes report on ZachXBT's timeline of Circle's inaction
- $285M Gone in 12 Minutes: How a Fake Token and Stolen Keys Gutted Drift Protocol -- CryptoTimes technical walkthrough of the fake token and vault draining sequence
- Drift Protocol Teams with Security Experts on Recovery After Exploit -- CryptoTimes update on Drift's recovery efforts with Asymmetric Research and OtterSec
- Solana Foundation launches security overhaul days after $270 million Drift exploit -- CoinDesk report on the Solana Foundation's STRIDE security program launched in response


