CarbonVote Token
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5oL3pJ…dWDvSummary
CarbonVote Token (CVT) is a fictitious Solana-based token deployed on March 12, 2026 as a purpose-built instrument in the DPRK-attributed $285 million exploit of Drift Protocol. The token was minted with a 750 million unit supply, wash-traded on Raydium to fabricate a $1.00 price history, and used as fraudulent collateral after attackers seized admin control of Drift via compromised multisig signatures. CVT itself has no independent utility or legitimate use case; it is documented exclusively as an attack vector.
Connected Entities
2 entities · 1 linked investigation- H7PiGqqUaanBovwKgEtreJbKmQe6dbq6VTrw6guy7ZgL→mentioned with→CarbonVote Token(50%)
- + 2 more
Connected Through
1 shared actor · 1 investigationDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- ◇H7PiGq…7ZgLwalletalso inDrift Protocol·52
Timeline(12 events)
September 2025
Approximate start of social engineering campaign. Individuals posing as representatives of a quantitative trading firm begin approaching Drift contributors at cryptocurrency conferences across multiple countries.
The Hacker NewsDecember 2025
Attackers establish an Ecosystem Vault on Drift and deposit over $1 million in real capital to build operational credibility, while conducting detailed product discussions with Drift contributors via Telegram.
Nexus Mutual Incident Report11 March 2026
On-chain staging begins. Attackers withdraw 10 ETH from Tornado Cash on Ethereum to fund token deployment infrastructure. Timing consistent with Pyongyang business hours.
TRM Labs12 March 2026
CarbonVote Token (CVT) deployed on Solana with 750 million total supply, approximately 80% attacker-controlled. A Raydium liquidity pool seeded with approximately $500 is established. Wash trading between attacker wallets begins to fabricate a $1.00 price history.
Chainalysis23 March 2026
Durable nonce exploitation phase begins. Attackers create durable nonce accounts and induce Security Council multisig signers to pre-sign malicious governance transactions through phishing or misleading signing requests.
BlockSec27 March 2026
Drift Protocol migrates its Security Council to a 2-of-5 multisig threshold and removes the operational timelock, eliminating the time-delay mechanism that could have detected malicious pre-signed transactions.
ChainalysisApril 2026
At approximately 16:05 UTC, two pre-signed transactions execute within four blockchain slots, transferring Drift administrative control to attacker address H7PiGqqUaanBovwKgEtreJbKmQe6dbq6VTrw6guy7ZgL. Attackers whitelist CVT as collateral, disable withdrawal limits, deposit 500 million CVT, and execute 31 withdrawal transactions over approximately 12 minutes, draining approximately $285 million in real assets.
BlockSec / ChainalysisApril 2026
Within 23 minutes of admin takeover, stolen assets begin bridging from Solana to Ethereum. Approximately $232 million in USDC is transferred via Circle's CCTP across more than 100 transactions.
Elliptic2 April 2026
Drift Protocol suspends services and begins publishing incident communications. BlockSec, Chainalysis, Elliptic, TRM Labs, and Hypernative publish initial forensic analyses.
The Record from Recorded Future News5 April 2026
Drift Protocol publishes its post-mortem attributing the exploit to a six-month North Korean state-sponsored intelligence operation, identifying UNC4736 (AppleJeus / Citrine Sleet) as the alleged threat actor.
CoinDesk16 April 2026
Drift Protocol publishes the Incident Recovery Update, confirming total verified losses of $295.7 million across 26 asset types and announcing initial recovery framework structure including Tether's proposed $127.5 million contribution.
Drift Protocol Official5 May 2026
Drift outlines full user recovery plan, with verified total losses cited at $295.4 million. Recovery token issuance structure, $100 million revenue-linked credit facility, and relaunch security requirements disclosed.
CoinDeskDecision Log
- hash: 22ynHwV2XWaaxYbyLMfb32i265QwitPz1hr2ywCL6gvc
- hash: Cbam6bTXLwrEZ3siMx38YzCZKqH5RzWeab228WGBBfdH
- hash: 4VAxL4vjJGJo1jnuWNXVJNCf545WVAm9KvhUTExEgZP4
This investigation is cryptographically anchored to the Solana blockchain (3 events). 13 of 14 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 5/10/2026, 6:08:39 AM
last updated: 7/25/2026, 10:29:59 AM
avoid.net — verified advice for a post-truth world