Skip to main content
AVOID.NET
Drift Protocol DPRK Exploit (April 2026)reviewed 2026-09-07 · 27 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Drift Protocol DPRK Exploit (April 2026) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

2 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #16[disputed][awaiting moderator]in section: Fund Movement and Laundering
    As of the April 16 recovery update, approximately $3.36 million in USDC had been frozen and approximately 130,259 ETH (roughly $31 million at the time) remained concentrated in four monitored wallets with limited successful off-ramping reported.
    reviewerAs of the April 16 recovery update, approximately $3.36 million in USDC had been frozen and approximately 130,259 ETH (roughly $31 million at the time) remained in four monitored wallets130,259 ETH at prevailing 2026 ETH prices is corroborated elsewhere at approximately $293 million, not the $31 million stated on the page — a roughly 9x undervaluation that would also be inconsistent internally with the page's own ~$295M total loss figure, since it implies almost all stolen value remained recoverable in the wallets. None of the three sources cited for this sentence (Elliptic, TRM Labs, Drift's April 16 update) actually contains either the USDC-frozen or ETH-holdings figures when fetched directly; both numbers instead trace to later reporting (e.g. The Defiant, businesswire-sourced coverage from around the May 5 recovery announcement).
    Proposed correction (not yet applied)
    As of subsequent reporting, approximately $3.36 million in USDC had been frozen and approximately 130,259 ETH (roughly $293 million at the time) remained concentrated in four monitored wallets with limited successful off-ramping reported.
  2. #17[disputed][awaiting moderator]in the timeline
    Drift Protocol publishes incident recovery update confirming $295,706,374.93 in losses; approximately $3.36 million USDC frozen; ~130,259 ETH (~$31 million) in monitored attacker wallets; public bounty offering 10% of recovered assets announced
    reviewerDrift Protocol publishes incident recovery update (April 16, 2026) confirming losses, USDC frozen, ETH in wallets, and a bounty offerSame underlying $31 million ETH-value error as the corresponding sentence in the Fund Movement and Laundering section, plus a date misattribution: the concrete 10% bounty figure and the ETH/USDC monitoring figures are documented in reporting around the May 5 recovery plan, not the April 16 update.
    Proposed correction (not yet applied)
    Drift Protocol publishes incident recovery update confirming $295,706,374.93 in losses; the update does not itself specify a USDC-frozen figure or ETH holdings (these figures, ~$3.36 million USDC frozen and ~130,259 ETH worth ~$293 million, appear only in later reporting); a bounty program was described as 'in development' rather than formally announced at 10%

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #26[unverifiable][awaiting moderator]in section: DPRK Attribution
    Mandiant's full forensic investigation was ongoing at the time of publication.
    reviewerMandiant's full forensic investigation was ongoing at the time of the post-mortem's publicationCould not independently verify this specific procedural detail about Mandiant's investigation status, nor find any subsequent reporting confirming Mandiant published a separate final report; not contradicted by any source found, but not confirmed either.

stale

2 claims

The claim was accurate when written but events since have overtaken it.

  1. #21[stale][awaiting moderator]in the summary
    Drift Protocol acknowledged the breach and published a token-based recovery framework backed by Tether ($127.5 million) and other partners, with a Q2 2026 protocol relaunch planned.
    reviewerA Q2 2026 relaunch was planned as a 'security-first' exchange with audits from Ottersec and Asymmetric required before resumption (summary)The Q2 2026 relaunch target reflected in the page's sources was accurate as of publication but has since been superseded: the protocol rebranded to Velocity DEX and, per subsequent reporting, moved to a private beta in July 2026 with public relaunch targeted for Q3 2026.
    Proposed correction (not yet applied)
    Drift Protocol acknowledged the breach and published a token-based recovery framework backed by Tether ($127.5 million) and other partners; a Q2 2026 relaunch was originally targeted but the exchange rebranded as Velocity DEX and pushed its public relaunch into Q3 2026 following a July 2026 private beta.
  2. #22[stale][awaiting moderator]in section: Recovery Plan and User Compensation
    A Q2 2026 relaunch was planned as a 'security-first' exchange with a narrowed product scope focused on perpetuals trading, enhanced multisig architecture, mandatory timelocks on administrative operations, and independent audits from Ottersec and Asymmetric required before resumption.
    reviewerA Q2 2026 relaunch was planned with a narrowed product scope, enhanced multisig, timelocks, and Ottersec/Asymmetric audits (recovery plan section)The Ottersec/Asymmetric audit detail is independently confirmed and remains accurate; only the Q2 2026 timing and the 'Drift' branding of the relaunched product are stale.
    Proposed correction (not yet applied)
    A relaunch was originally planned for Q2 2026 as a 'security-first' exchange with a narrowed product scope focused on perpetuals trading, enhanced multisig architecture, mandatory timelocks on administrative operations, and independent audits from Ottersec and Asymmetric required before resumption; the exchange subsequently rebranded as Velocity DEX and the public relaunch slipped to Q3 2026.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #3[partially supported][awaiting moderator]in section: Incident Overview
    The hack wiped out more than half of Drift's total value locked (TVL), which fell from approximately $550 million to under $250 million.
    reviewerDrift's TVL fell from approximately $550 million to under $250 millionThe $550M starting TVL and >50% loss are well corroborated, but the specific 'under $250 million' floor is contradicted by at least one reputable secondary source citing 'under $300 million'; treated as a mischaracterization of precision rather than a clear factual reversal.

confirmed

21 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Incident Overview
    Drift Protocol, the largest decentralized perpetual futures exchange on the Solana blockchain, was exploited on April 1, 2026, resulting in losses subsequently confirmed by the protocol at $295,706,374.93.
    reviewerDrift Protocol was exploited on April 1, 2026, with losses confirmed at $295,706,374.93The precise loss figure was confirmed by Drift's own post-incident accounting after initial press reports used rounder preliminary estimates ($270-286M); the page's use of the exact figure is accurate and well-sourced.
  2. #2[confirmed][no action needed]in section: Incident Overview
    The attack was executed in approximately twelve minutes and involved thirty-one withdrawal transactions.
    reviewerThe attack was executed in approximately twelve minutes via thirty-one withdrawal transactionsMultiple independent technical writeups corroborate both the transaction count and duration.
  3. #4[confirmed][no action needed]in section: Incident Overview
    The incident is regarded as the largest DeFi hack of 2026 and the second-largest exploit in Solana's history after the $326 million Wormhole bridge hack of 2022.
    reviewerThe Drift hack is the largest DeFi hack of 2026 and the second-largest Solana exploit after the $326 million Wormhole hack of 2022Widely and consistently reported across multiple independent outlets.
  4. #5[confirmed][no action needed]in section: DPRK Attribution
    The attribution carries a stated confidence level of medium-high and is supported by: on-chain fund flows connecting the attacker wallets to proceeds from the October 2024 Radiant Capital hack (previously attributed to UNC4736 by Mandiant); laundering methodologies consistent with prior DPRK-linked operations; operational persona overlaps with known DPRK activity; and timing of early preparatory transactions around 09:00 Pyongyang Standard Time on March 12, 2026.
    reviewerDrift's post-mortem attributed the exploit to UNC4736 with medium-high confidence, supported by fund-flow overlap with the October 2024 Radiant Capital hackAttribution language and confidence level match the primary cited source closely.
  5. #6[confirmed][no action needed]in section: DPRK Attribution
    The Drift exploit represents, according to Elliptic, the eighteenth DPRK-linked crypto incident tracked in 2026, bringing total year-to-date DPRK theft to over $300 million.
    reviewerThe Drift exploit is the eighteenth DPRK-linked crypto incident Elliptic tracked in 2026, bringing YTD DPRK theft over $300 millionDirectly matches the cited source's own language.
  6. #7[confirmed][no action needed]in section: DPRK Attribution
    TRM Labs separately reported that North Korean state-backed hackers accounted for approximately 76 percent of global crypto hack losses in 2026.
    reviewerTRM Labs reported North Korean state-backed hackers accounted for approximately 76 percent of global crypto hack losses in 2026Well corroborated across multiple independent reports of the same TRM Labs data.
  7. #8[confirmed][no action needed]in section: Broader DPRK Crypto Threat Context
    following the Radiant Capital hack in October 2024 (attributed to the same group, UNC4736, with a $50-53 million loss)
    reviewerThe Radiant Capital hack (October 2024) was attributed to the same group, UNC4736, with a $50-53 million lossThe $50-53 million range accurately reflects the spread of figures reported at different stages of the Radiant Capital incident.
  8. #9[confirmed][no action needed]in section: Social Engineering Operation (Fall 2025 – March 2026)
    First, a contributor cloned a malicious Microsoft Visual Studio Code (or Cursor) project containing a weaponized 'tasks.json' file; simply opening the folder executed arbitrary code silently due to the 'runOn: folderOpen' option, a known VSCode/Cursor vulnerability. Second, a separate contributor was persuaded to download a wallet application via Apple's TestFlight beta distribution platform, which bypasses App Store security review.
    reviewerTwo infection vectors were used: a weaponized VSCode/Cursor tasks.json file with runOn:folderOpen, and a wallet app distributed via Apple TestFlight bypassing App Store reviewNear-verbatim match to the cited source's technical description.
  9. #10[confirmed][no action needed]in section: Technical Attack Mechanism: Durable Nonces and Fake Collateral
    The attackers created four durable nonce accounts on March 23, 2026 — two associated with legitimate Security Council members and two controlled by the attacker — meaning the attacker had already obtained valid pre-signatures from two of the five required council members.
    reviewerFour durable nonce accounts were created on March 23, 2026 — two tied to legitimate Security Council members and two attacker-controlledCorroborated by an independent technical post-mortem (BlockSec) in addition to the cited CoinDesk piece.
  10. #11[confirmed][no action needed]in section: Technical Attack Mechanism: Durable Nonces and Fake Collateral
    On March 27, Drift executed a planned Security Council migration, and on March 30, a new durable nonce account appeared tied to an updated multisig member, indicating the attacker had re-obtained the necessary two-of-five approval threshold following the migration.
    reviewerOn March 27 Drift executed a Security Council migration, and on March 30 a new durable nonce account appeared re-securing the 2-of-5 thresholdConsistent with independently corroborated technical timeline.
  11. #12[confirmed][no action needed]in section: Technical Attack Mechanism: Durable Nonces and Fake Collateral
    On April 1, two transactions four slots apart on the Solana blockchain created and approved a malicious admin transfer, then executed it, granting the attacker full administrative control within minutes.
    reviewerOn April 1, two transactions four slots apart created and approved a malicious admin transfer, granting the attacker full administrative controlMatches technical detail independently reported by a blockchain security firm.
  12. #13[confirmed][no action needed]in section: Technical Attack Mechanism: Durable Nonces and Fake Collateral
    Using this control, attackers deployed a worthless token designated CarbonVote Token (CVT), with a total supply of 750 million tokens created on March 12, 2026 and seeded with a small amount of liquidity.
    reviewerAttackers deployed CarbonVote Token (CVT) with a 750 million total supply, created March 12, 2026Corroborated by two independent research sources.
  13. #14[confirmed][no action needed]in section: Technical Attack Mechanism: Durable Nonces and Fake Collateral
    The attacker then whitelisted CVT as eligible collateral within the protocol, deposited 500 million CVT, and used the inflated collateral value to withdraw approximately $285-295 million in real assets including USDC, SOL, JLP tokens, cbBTC, wBTC, and various liquid staking tokens from three core vaults: JLP Delta Neutral, SOL Super Staking, and BTC Super Staking.
    reviewerThe attacker whitelisted CVT as collateral, deposited 500 million CVT, and drained the JLP Delta Neutral, SOL Super Staking, and BTC Super Staking vaultsVault names, deposit amount, and asset list are consistently corroborated.
  14. #15[confirmed][no action needed]in section: Fund Movement and Laundering
    Preparatory on-chain activity included an initial 10 ETH withdrawal from Tornado Cash on March 11, 2026, used to fund CVT deployment on March 12.
    reviewerPreparatory on-chain activity included an initial 10 ETH Tornado Cash withdrawal on March 11, 2026, used to fund CVT deploymentMatches the cited source's own language closely.
  15. #18[confirmed][no action needed]in section: Recovery Plan and User Compensation
    Announced funding sources include: approximately $3.8 million in remaining protocol assets; up to $127.5 million from Tether (performance-tied and contingent); up to $20 million from strategic partners; and ongoing exchange revenue contributions after relaunch.
    reviewerAnnounced recovery funding sources: ~$3.8 million remaining protocol assets, up to $127.5 million from Tether, up to $20 million from partnersFigures matched exactly in independently fetched reporting.
  16. #19[confirmed][no action needed]in section: Recovery Plan and User Compensation
    A public bounty offering 10 percent of recovered assets was launched to incentivize information leading to fund recovery.
    reviewerA public bounty offering 10 percent of recovered assets was launchedAccurate when attached to the May 5 recovery plan announcement (as it is in this section), unlike the premature April 16 timeline reference to the same figure.
  17. #20[confirmed][no action needed]in section: Recovery Plan and User Compensation
    The protocol also announced it would migrate its settlement layer from USDC to USDT.
    reviewerThe protocol announced it would migrate its settlement layer from USDC to USDTCorroborated.
  18. #23[confirmed][no action needed]in section: Recovery Plan and User Compensation
    independent audits from Ottersec and Asymmetric required before resumption
    reviewerIndependent audits from Ottersec and Asymmetric are required before resumptionIndependently corroborated audit-firm assignments.
  19. #24[confirmed][no action needed]in section: Regulatory and Legal Context
    However, the U.S. Department of the Treasury's Office of Foreign Assets Control described North Korea's cyber operations and remote IT worker schemes as a meaningful source of regime revenue in a March 2026 sanctions announcement.
    reviewerOFAC described DPRK cyber operations and remote IT worker schemes as a meaningful revenue source in a March 2026 sanctions announcementIndependently corroborated OFAC action from March 2026 matches the described theme, though the page does not cite the OFAC action directly by name.
  20. #25[confirmed][no action needed]in section: Regulatory and Legal Context
    Tether cited its track record of coordinating with more than 310 law enforcement agencies across 64 countries in announcing its involvement in the recovery plan.
    reviewerTether cited coordination with more than 310 law enforcement agencies across 64 countriesMatches Tether's publicly stated figures from the relevant period.
  21. #27[confirmed][no action needed]in section: Security Failures and Post-Incident Recommendations
    The Security Council's 2-of-5 multisig threshold was insufficient against a targeted social engineering campaign that could compromise individual signers' devices.
    reviewerStructural vulnerabilities included a 2-of-5 multisig threshold, absence of timelocks, no real-time nonce monitoring, and inadequate collateral whitelisting reviewConsistent across multiple independent post-incident technical analyses.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.