Hackers drain $286 million from Drift Protocol in suspected North Korea-linked exploit
Drift Protocol suffered a major exploit on April 1 that drained roughly $286 million from its vaults, making it one of the biggest crypto thefts of 2026 so far. Drift said an attacker gained unauthorized access through a “novel attack involving durable nonces,” then paused deposits and withdrawals while it investigated.
The early evidence does not point to a smart contract bug. CoinDesk reported that the exploit centered on Solana durable nonces, a legitimate transaction feature, while several public incident summaries said Drift’s contracts themselves held up.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The North Korea link remains a strong suspicion, not a final public attribution. Elliptic said it found multiple indicators suggesting the exploit links to DPRK actors, but it stopped short of calling the case fully confirmed.
What happened
According to public incident summaries, the attacker quickly emptied major Drift vaults, including the JLP Delta Neutral vault and the SOL and BTC Super Staking vaults. One of the largest moves involved about 41.7 million JLP tokens, which on-chain analysts valued at roughly $155 million at the time.
Drift’s own public statement said the platform faced an active attack and immediately stopped normal activity to contain the damage. The team also said it was working with forensic partners, law enforcement, and ecosystem teams to build a full picture of the incident.
The loss also hit the protocol’s locked value hard. Public reporting and on-chain summaries said Drift’s total value locked fell from around $550 million to below $250 million after the exploit.
How the stolen funds moved
Elliptic said the attacker’s wallet appeared about eight days before the exploit and received a small test transfer from a Drift vault before the main theft. That pattern suggests preparation and staging rather than a random hit.
After the theft, Elliptic said the attacker used a Solana DEX aggregator to swap much of the stolen mix into USDC, then bridged funds to Ethereum and converted them into ETH. Cross-chain movement like that makes tracing harder and gives the attacker more room to launder assets.
CoinDesk’s reporting aligns with that sequence and adds an important detail. It says the exploit relied on durable nonces to delay execution of pre-signed transactions, which gave the attacker a way to turn privileged access into rapid fund movement.
Why North Korea is part of the conversation
Elliptic said the Drift exploit carries multiple indicators associated with DPRK-linked crypto theft. It also said this would be the eighteenth DPRK-linked crypto theft it has tracked in 2026, with more than $300 million stolen this year if the attribution holds.
That broader claim fits long-running US government warnings. The Treasury Department has repeatedly said North Korean hacking groups steal digital assets and other funds to support the regime’s weapons and missile programs.
Still, the public case remains at the “suspected” stage. No public US government statement I found has formally attributed the Drift exploit itself to North Korea as of April 7, 2026.
Key facts at a glance
| Item | What we know |
|---|---|
| Date | April 1, 2026 |
| Amount stolen | About $286 million |
| Suspected method | Unauthorized access plus durable nonce abuse, not a disclosed contract bug |
| Drift response | Deposits and withdrawals paused, investigation launched |
| DPRK link | Elliptic says indicators suggest DPRK involvement, but public attribution remains provisional |
What the incident appears to show
- The exploit looks more like privileged access abuse than a straightforward smart contract flaw.
- The attacker appears to have staged the operation in advance.
- Cross-chain laundering began quickly after the theft.
- The North Korea angle comes from Elliptic’s indicators, not from a final official attribution yet.
FAQ
Current reporting points to unauthorized access combined with abuse of Solana durable nonces. CoinDesk said the incident did not involve a bug in Drift’s code.
Yes. Drift publicly said an attacker gained unauthorized access through a novel durable nonce attack and that it paused deposits and withdrawals during the response.
Not publicly confirmed. Elliptic said it found multiple indicators suggesting a DPRK link, but that is still an intelligence assessment rather than a final official attribution.
The theft shows how a single access failure at an admin or operational layer can cause losses on the scale of a top-tier DeFi hack even when the underlying contracts are not the main point of failure.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages