DeFi Intel

Drift Protocol DPRK Admin-Access and Fake-Oracle Exploit (April 1, 2026)

Date
2026-04-01
Loss
$285M
Category
DeFi exploit (social engineering / governance takeover)
Attack vector
A six-month DPRK social-engineering operation compromised Security Council members' devices, then abused Solana durable nonces to obtain pre-signed multisig approvals granting admin control. Attackers whitelisted a self-created fake token (CarbonVote/CVT) with a wash-traded ~$1 oracle price, deposited it as collateral, and drained ~$285M of real assets from three vaults in roughly 12 minutes.
Attribution
Attributed by Drift with medium-high confidence to UNC4736 (aka AppleJeus, Citrine Sleet, Golden Chollima, Gleaming Pisces); Mandiant later tied the operation to DPRK group UNC6862. On-chain staging traced to the October 2024 Radiant Capital attackers. TRM Labs and Elliptic corroborated DPRK indicators; ZachXBT tracked laundering and criticized Circle's inaction.

Overview

On April 1, 2026, Drift Protocol, the largest decentralized perpetual-futures exchange on Solana, was drained of approximately $285M in roughly twelve minutes, making it the largest DeFi exploit of 2026 and the second-largest security incident in Solana history after the $326M Wormhole bridge hack of 2022. The attack was not a smart-contract exploit; Drift's audited code executed exactly as designed. Instead, a DPRK-linked crew ran a six-month human-intelligence operation, first making contact at a crypto conference in the fall of 2025 while posing as a legitimate quantitative trading firm, onboarding an Ecosystem Vault, depositing over $1M of real capital, and building trust through Telegram, working sessions, and in-person meetings across several countries. The intermediaries were not North Korean nationals but third parties with fully constructed identities engineered to survive due diligence. Using a known code-execution vulnerability in VSCode and Cursor plus a malicious TestFlight app presented as a wallet product, the attackers compromised contributor devices touching the multisig. They then abused Solana durable nonces, a legitimate feature that lets transactions be pre-signed and executed later without expiring, to obtain two-of-five Security Council approvals for transactions that appeared routine but actually transferred protocol admin authority. Critically, Drift had removed its governance timelock on March 27, five days before execution, eliminating the detection window. In parallel, the attackers manufactured a fake asset, CarbonVote Token (CVT), minting hundreds of millions of units, seeding a few thousand dollars of Raydium liquidity, and wash-trading a price history near $1 that Drift's oracle ingested. On April 1 they whitelisted CVT as collateral, raised withdrawal limits, deposited roughly 500M CVT, and executed 31 withdrawals draining USDC, JLP, cbBTC, WETH, and other assets. Over $230M was bridged to Ethereum via Circle's CCTP across 100-plus transactions; Circle declined to freeze the USDC, drawing an eventual class action. Tether led an ~$148M rescue and Drift pivoted settlement from USDC to USDT.

Timeline of events

The operation began in the fall of 2025, when individuals posing as a quantitative trading firm first approached Drift contributors at a major crypto conference. Over the following months they built credibility: an Ecosystem Vault was onboarded, more than $1M of the attackers' own capital was deposited, and contact was maintained through a Telegram group, working sessions, and in-person meetings across several countries. Staging turned concrete in March 2026. On March 11 the crew withdrew 10 ETH from Tornado Cash, and on March 12 those funds were used to create the CarbonVote Token (CVT). Between March 23 and March 30 the attackers created durable-nonce accounts and, exploiting compromised signer devices, obtained pre-signed multisig approvals. On March 27 Drift executed a planned Security Council migration to a two-of-five multisig and removed its timelock; by March 30 fresh nonce activity tied to an updated multisig member showed the attackers had re-obtained the required threshold. On April 1, beginning around 16:05 UTC, two transactions roughly a second apart proposed and approved the transfer of admin authority to an attacker address. Over the next roughly 2.5 hours (the core drain executing in about 12 minutes), CVT was whitelisted as collateral, withdrawal limits were raised, ~500M CVT was deposited, and 31 withdrawals emptied three core vaults. Stolen assets were swapped to USDC via a Solana DEX aggregator and bridged to Ethereum, with the first funds arriving roughly 23 minutes after takeover. Drift halted deposits and withdrawals and confirmed the exploit publicly on April 2.

Attack mechanism

The exploit chained three distinct capabilities, none of which touched a Solidity or Rust contract bug. First, human compromise: the attackers spent six months earning insider access, then compromised developer machines that touched the Security Council multisig. Drift identified a malicious TestFlight application, presented as the fake firm's wallet product, and a known code-execution vulnerability in the VSCode and Cursor editors, exploited since late 2025, where merely opening a file or folder could silently run arbitrary code with no prompt. Second, the durable-nonce abuse: Solana durable nonces replace an expiring recent-blockhash with a fixed one-time value, allowing a transaction to be signed once and executed validly at any later time. By tricking two of the five Security Council signers into pre-approving transactions that looked routine, the attackers held dormant, pre-signed instructions that later granted admin control, all without ever stealing a private key or cracking the multisig. Third, the fake-oracle collateral: the attackers minted CVT, controlled roughly 80% of supply, seeded a few thousand dollars of Raydium liquidity, and wash-traded a price history near $1 that Drift's oracle treated as genuine. With admin authority in hand they whitelisted CVT as collateral, lifted withdrawal limits, deposited a nominal ~$500M of worthless CVT against the manufactured price, and withdrew real assets. The removal of the timelock on March 27 was the force multiplier: it deleted the delay that would otherwise have surfaced the malicious admin change before funds could move.

Root cause analysis

The root cause was operational security, not code. Drift's contracts processed valid, properly signed multisig transactions and behaved exactly as written; the trust boundary that failed sat around the contracts, in the humans and devices authorized to govern them. Several compounding decisions turned a targeted intrusion into a catastrophic drain. The two-of-five Security Council threshold meant only two compromised signers were needed, and those signers approved transactions on the same machines used for development, where the TestFlight and editor compromises lived. The March 27 removal of the governance timelock eliminated the single control most likely to have caught an unexpected admin transfer, collapsing the window between approval and irreversible execution to essentially zero. Signers evidently could not fully verify what they were approving, so durable-nonce transactions engineered to look routine passed review. Finally, the collateral-whitelisting and oracle path trusted a freshly listed token's market price without adequate provenance checks, so a wash-traded asset with negligible real liquidity could be booked at par. Each of these, timelock enforcement, a higher multisig threshold, independent transaction verification, dedicated air-gapped signing devices, contract-level address whitelisting, and continuous on-chain monitoring, would on its own have likely blunted or prevented the attack. Their simultaneous absence, engineered in part by six months of adversary patience, is the real root cause.

Initial response and Circle freeze controversy

Drift suspended deposits and withdrawals once the drain was detected and began public disclosure on April 2, publishing a fuller post-mortem on April 5 that framed the incident as a six-month North Korean intelligence operation. The DRIFT governance token fell more than 40% and Drift's TVL dropped from roughly $550M to under $300M within an hour. The most contentious thread was Circle's response. More than $230M of the stolen funds moved as USDC, bridged from Solana to Ethereum through Circle's own Cross-Chain Transfer Protocol (CCTP) across 100-plus transactions over several hours. On-chain investigator ZachXBT publicly accused Circle of being asleep at the switch, noting the attackers held USDC for one to three hours before swapping and pointedly avoided converting to USDT, apparently confident Circle would not freeze the funds while, by contrast, Tether had a track record of freezing illicit balances. Critics highlighted that Circle had frozen 16 unrelated wallets just nine days earlier in a separate civil matter, demonstrating both capability and willingness to act. Circle CEO Jeremy Allaire defended the company, saying Circle freezes USDC only at the direction of law enforcement or the courts and that acting outside established legal process in private disputes would raise a significant moral quandary. The dispute reframed stablecoin issuers as de facto emergency responders and set up both the litigation and the USDC-to-USDT pivot that followed.

Funds tracking and laundering

The laundering followed a recognizable DPRK playbook. Within the drain, stolen JLP, USDC, SOL, cbBTC, WBTC, and liquid-staking tokens were swapped through a Solana DEX aggregator into USDC, then bridged to Ethereum, with the primary drainer wallet having been pre-funded via NEAR roughly eight days before the attack and staging funds routed through Backpack, Wormhole, and Tornado-Cash-prefunded addresses. Asset-level figures reported by Chainalysis and others put JLP at roughly $155-159M, USDC around $60-71M, cbBTC at ~$11.3M, USDT ~$5.6M, USDS ~$5.3M, WETH ~$4.7M, dSOL ~$4.5M, WBTC ~$4.4M, FARTCOIN ~$4.1M, and JitoSOL ~$3.6M, alongside a dozen smaller balances. On Ethereum the proceeds were consolidated through DEXes, converted to ETH, splintered across hundreds of wallets, and partially cycled through Tornado Cash, with a significant portion sitting in identified holding wallets. Elliptic characterized the event as roughly $286M and, at the time, the eighteenth DPRK-linked incident it had tracked in 2026, cumulatively over $300M. Attribution rested on on-chain overlap with the Radiant Capital attackers and operational overlaps in the personas used, with Mandiant's later forensic work naming UNC6862. The deliberate avoidance of USDT during bridging became a central evidentiary point in the subsequent litigation against Circle.

Legal and regulatory aftermath

The incident's legal center of gravity became Circle rather than Drift. On April 14, 2026, Gibbs Mura, A Law Group, with co-counsel Joshua Joseph Law Firm LLC, filed what it described as the first class action on behalf of affected Drift investors, targeting Circle Internet Financial. The complaint alleged that Circle knowingly allowed attackers tied to North Korea to offload roughly $230M of USDC through Circle's own token and CCTP bridge over several hours across 100-plus transactions, despite possessing the technical and contractual authority to freeze the funds, and pointed to Circle's freeze of 16 unrelated wallets nine days earlier as proof of capability. Circle's public position, articulated by Jeremy Allaire, was that it acts only at the direction of law enforcement or courts and that freezing in private disputes would create a moral quandary. The suit crystallized a broader regulatory question about whether centralized stablecoin issuers bear affirmative obligations to intervene against known theft, a question with implications well beyond Drift as USDC and USDT increasingly underpin DeFi settlement. Separately, the DPRK attribution drew the incident into the ambit of U.S. sanctions and Treasury interest in Lazarus-adjacent activity, though no formal government attribution or indictment had been issued as of mid-2026. The event also sharpened scrutiny of how DeFi protocols disclose governance-security posture to users.

Industry implications

Drift became the defining 2026 case that DeFi's frontier risk had shifted from code to people and process. The Solana Foundation responded on April 7 by unveiling Stride, a structured security-evaluation program led by Asymmetric Research that assesses DeFi protocols against eight security pillars and funds ongoing operational-security and threat monitoring for protocols above $10M TVL that pass, alongside the Solana Incident Response Network (SIRN), a membership group of security firms for real-time crisis response. The incident hardened several norms: governance timelocks on admin actions came to be treated as non-negotiable rather than optional convenience trade-offs; multisig thresholds and dedicated, air-gapped signing devices separated from developer machines became baseline expectations; and any device touching a multisig came to be treated as a first-class attack target. The durable-nonce vector prompted wallets and signing tooling to surface clearer warnings about offline-signed, non-expiring transactions. The Circle freeze debate pushed stablecoin issuers toward clearer, faster incident-response policies and revived interest in issuer-level controls as a systemic backstop. And the fake-oracle collateral path reinforced that newly listed assets with thin, wash-traded liquidity must not be booked at face value, tightening collateral-onboarding and oracle-provenance standards across lending and perps venues. Collectively the response mirrored the post-Bybit shift in exchange custody, now applied to DeFi governance.

Verdict and lessons

Drift is the canonical demonstration that audited, correctly functioning smart contracts are no defense when the humans and devices that govern them are compromised, and that a patient, well-funded adversary can defeat governance without ever touching a private key or a contract bug. The contracts did exactly what they were told; the failure was that the wrong parties were doing the telling, through pre-signed transactions the legitimate signers never meaningfully understood. The concrete lessons are unambiguous. First, never remove governance timelocks on admin-critical actions; the delay is the detection window, and its removal on March 27 was decisive. Second, treat every device that touches a multisig as hostile, isolate signing onto dedicated hardware, and assume developer machines are compromised. Third, require independent, human-legible verification of what is being signed, because durable-nonce and blind-signing attacks exploit the gap between what a signer thinks they approve and what they actually authorize. Fourth, harden collateral onboarding and oracle provenance so that thinly traded, wash-traded assets cannot be booked at par. Fifth, recognize that stablecoin issuers are now systemic incident responders whose freeze policies materially affect recovery, and design assuming they may not act. For the threat-model picture, Drift confirms that DPRK operations against DeFi are multi-month human-intelligence campaigns, not opportunistic code hunts, demanding exchange-grade operational security from every protocol of consequence.

Recovery

Drift secured a rescue package of up to ~$147.5M (up to $127.5M from Tether plus ~$20M from partners), including a ~$100M revenue-linked credit facility, an ecosystem grant, and market-maker loans, and pivoted settlement from USDC to USDT with Tether market-making support. Rather than instant reimbursement, Drift issued transferable SPL recovery tokens (one per $1 of verified loss), backing a recovery pool seeded with the protocol's ~$3.8M residual assets and topped up via quarterly exchange revenue, the Tether facility, and partner funds; full repayment could take years. Relaunch as a security-first, USDT-based perps DEX targeted Q2 2026, contingent on independent audits (OtterSec, Asymmetric) with new multisig controls, timelocks, key rotation, and reduced product scope; Noah Prince joined as Head of Protocol and Gauntlet alumni were engaged for risk.

Key lessons

  • Never remove governance timelocks on admin-critical actions; the delay is the detection window, and its removal on March 27 was the decisive enabler
  • Treat every device touching a multisig as hostile; isolate signing to dedicated hardware and assume developer machines are compromised
  • Require independent, human-legible verification of every signed transaction; durable-nonce and blind-signing defeat signers who cannot see what they authorize
  • Harden collateral onboarding and oracle provenance so thinly traded, wash-traded assets cannot be booked at par as collateral
  • Assume stablecoin issuers may not freeze stolen funds in time; DPRK campaigns are patient human-intelligence operations demanding exchange-grade opsec

Frequently asked questions

What happened in the Drift Protocol DPRK Admin-Access and Fake-Oracle Exploit?

Drift Protocol, Solana's largest perpetual-futures DEX, lost ~$285M on April 1, 2026 in the year's biggest DeFi exploit and the second-largest Solana hack after Wormhole (2022). It was not a code bug: a six-month DPRK campaign (UNC4736, later tied by Mandiant to UNC6862) compromised Security Council signers via a malicious TestFlight app and a VSCode/Cursor exploit, abused Solana durable nonces to obtain pre-signed multisig admin approvals, and exploited the March 27 removal of the governance timelock. With admin control they whitelisted a wash-traded fake token (CVT) at a ~$1 oracle price and drained three vaults in ~12 minutes. Over $230M was bridged to Ethereum via Circle's CCTP; Circle declined to freeze it, drawing a Gibbs Mura class action. Tether led an ~$148M rescue, Drift pivoted from USDC to USDT and issued SPL recovery tokens for verified losses.

How much was lost?

Approximately $285M was lost on 2026-04-01.

How did the attack work?

A six-month DPRK social-engineering operation compromised Security Council members' devices, then abused Solana durable nonces to obtain pre-signed multisig approvals granting admin control. Attackers whitelisted a self-created fake token (CarbonVote/CVT) with a wash-traded ~$1 oracle price, deposited it as collateral, and drained ~$285M of real assets from three vaults in roughly 12 minutes.

Who was responsible?

Attributed by Drift with medium-high confidence to UNC4736 (aka AppleJeus, Citrine Sleet, Golden Chollima, Gleaming Pisces); Mandiant later tied the operation to DPRK group UNC6862. On-chain staging traced to the October 2024 Radiant Capital attackers. TRM Labs and Elliptic corroborated DPRK indicators; ZachXBT tracked laundering and criticized Circle's inaction.

Were the funds recovered?

Drift secured a rescue package of up to ~$147.5M (up to $127.5M from Tether plus ~$20M from partners), including a ~$100M revenue-linked credit facility, an ecosystem grant, and market-maker loans, and pivoted settlement from USDC to USDT with Tether market-making support. Rather than instant reimbursement, Drift issued transferable SPL recovery tokens (one per $1 of verified loss), backing a recovery pool seeded with the protocol's ~$3.8M residual assets and topped up via quarterly exchange revenue, the Tether facility, and partner funds; full repayment could take years. Relaunch as a security-first, USDT-based perps DEX targeted Q2 2026, contingent on independent audits (OtterSec, Asymmetric) with new multisig controls, timelocks, key rotation, and reduced product scope; Noah Prince joined as Head of Protocol and Gauntlet alumni were engaged for risk.

Related