It was the fall of 2025, and several Drift Protocol contributors were at a major cryptocurrency conference. 

The contributors to Drift –  a major decentralized finance (DeFi) platform built on the Solana blockchain – were reportedly approached by a group of individuals that said they were with a quantitative trading firm. The group was interested in integrating on the protocol – and to the contributors, who help to maintain and improve the decentralized exchange – it seemed like a good fit. The group of people was technically fluent, understood how Drift worked, and had professional backgrounds. 

Over the course of the next six months, the Drift contributors and supposed representatives from the firm held many “substantive conversations” via a Telegram group about trading strategies and integrations. The group asked detailed product questions, onboarded an Ecosystem Vault that required filling out forms with in-depth details about strategy, and met in person again at multiple industry conferences. All the while, the group shared links for projects and tools they said they were building on their end – all “standard practice for trading firms,” according to Drift.

But the group wasn’t with a quantitative trading firm.

They were working with what Drift believes is a North Korean-linked threat group, as part of an insanely complex social engineering scheme that led to $285 million in user assets being drained from the DeFi protocol on April 1, 2026.  

‘This is Not an April Fools Joke’

On April 1, Drift said it was observing “unusual activity” on the protocol, and promptly suspended deposits and withdrawals. Attackers were siphoning $285 million from the protocol, marking the largest DeFi hack of 2026 and causing the DRIFT token to fall over 40 percent.

It took attackers just 12 minutes for users to drain the assets, according to TRM Labs. But according to an incident update by Drift posted over the weekend, the lead up to the attack was much longer at almost half a year.

The report, which shared more details about the attack vector and how the operation had been staged, tied the attack to a group linked to the DPRK. In a twist, the individuals that had initially approached the Drift contributors at the crypto conference – who weren't North Korean nationals, but third-party intermediaries – were actually deployed by DPRK threat actors “to conduct face-to-face relationship-building,” setting the stage for the attack. 

“After the exploit on April 1 happened, a thorough forensic review of known affected devices, accounts, and communication histories was conducted,” according to Drift. “Interactions with this trading group came into focus as the likely intrusion vector. Right as the exploit happened, their Telegram chats and malicious software had been completely scrubbed.”

Piecing Together the Attack

In the days after April 1, Drift and the broader DeFi community were left piecing together how the attack had occurred. On April 2, Drift said the incident was enabled in part by pre-signed durable nonce transactions. This is a specific type of transaction used on Solana. Because this type of transaction is signed ahead of time and remains valid for a long period of time, it allowed attackers to delay the execution of their transactions. Between March 23 and March 30, attackers created multiple durable nonce accounts.

Attackers were also able to compromise multiple Drift Security Council multisig signer approvals, according to the April 2 update, likely through targeted social engineering or transaction misrepresentation. Multisig is a multi-signature wallet that’s used by the protocol, meaning multiple people must approve a transaction before it goes live. The approvals in this case were reportedly used for pre-signing transactions that seemed to be routine, but that actually included hidden authorizations for critical admin actions.

With these two parts setting the stage, Drift, which since the attack has engaged Mandiant for the investigation, said there are likely three attack vectors specifically tied to the hack.

In one case, a contributor might have been compromised after cloning a code repository that the threat group had shared (believing it was a frontend for their vault). Another contributor downloaded a TestFlight app that the group said was their wallet product. 

The behind-the-scenes moves by the attackers in March. Credit: TRM Labs

“For the repository-based vector, one possibility is a known VSCode and Cursor vulnerability that the security community was actively flagging throughout December 2025 through February 2026,” according to Drift. “Simply opening a file, folder, or repository in the editor was sufficient to silently execute arbitrary code, with no prompt or indication to the user, clicks, permissions dialog or warning of any kind.”  

During the immediate lead up to the attack itself, according to TRM Labs, attackers made a fake token called CarbonVote Token, which they listed “as valid collateral on Drift, raised withdrawal limits to extreme levels, and deposited hundreds of millions in CVT against that manufactured price.” 

“The attacker spent weeks manufacturing legitimacy for a fake token — CarbonVote Token (CVT) — minting 750 million units, seeding just a few thousand dollars in liquidity on Raydium, and using wash trading to build a price history near USD 1,” according to TRM Labs. “Drift's oracles picked up that artificial signal and treated CVT as a real asset.”

Then, the attackers made 31 withdrawal transactions in the 12 minutes on April 1.

‘The Confidence of the Hackers Was Staggering’

According to TRM Labs, DeFi platforms should place timelocks on governance and admin actions; implement defense-in-depth practices; and ensure multisig hygiene.

For attackers, Drift Protocol is a high-value target. Drift is the largest decentralized perpetual futures exchange on the Solana blockchain. Users can trade perpetual contracts on crypto assets, meaning they can bet on prices going up or down. The protocol held billions in user assets. 

DeFi and crypto hacks in general have led to heists of staggering amounts of money – even more than that of Drift, including the 2025 Bybit attack that is the largest crypto theft in history at $1.4 billion; and the $624 million 2022 Ronin Network hack.

However, the amount of operations, preparation, and resources poured into the Drift Protocol hack is striking. According to TRM Labs, each bridging transaction moved “hundreds of thousands or, more often, millions in USDC, far outstripping the speed and aggressiveness of even the Bybit laundering of 2025.”

“The confidence of the hackers was staggering,” said the team at TRM Labs.