Skip to main content
Sign in

Drift Protocol

avoid.net/drift52/100·88% conf.
[VERIFIED][src:defillama]
anchored·5pATPD…1Cts

Summary

Drift Protocol is a decentralized perpetual futures exchange built on the Solana blockchain, founded in 2021 by Cindy Leow, David Lu, and co-founders. The protocol has experienced two significant security incidents: a $14.5 million PnL accounting bug in May 2022 triggered by the LUNA collapse (fully reimbursed), and a catastrophic $285–286 million exploit on April 1, 2026, attributed with medium-high confidence to the North Korean state-sponsored threat actor UNC4736 (also tracked as Lazarus Group, AppleJeus, and Citrine Sleet), which constituted the largest DeFi hack of 2026. A $295 million recovery plan involving Tether-led financing and user-issued recovery tokens was announced in May 2026; a class action lawsuit was simultaneously filed against Circle Internet Financial.

Connected Entities

22 entities · 3 linked investigations
Wallets
2eSB4T…oPhQHkGz4K…pZES4twoCx…pL7U3nPK19…NoMwSanctum Markets2fFKAP…FhogDrift Staked SOL (dSOL)FjAZsH…L8uiDLrX7o…7jVcZGeHG7…HxE7oTpBAB…ycn1H7PiGq…7ZgL5SyZwK…52v669qTU2…Ng93T9LTkf…rHFX
Individuals
David LuCindy Leow
Organizations
DriftDrift Labs
Tokens
Drift Staked SOL
Protocols
Kamino Reserve 1Drift Protocol
Relationships
  • Drift Staked SOL (dSOL)associated withDrift(80%)
  • + 37 more

Connected Through

3 shared actors · 3 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Live On-Chain Activity

1 address watched · via Helius
No on-chain activity recorded yet for the addresses linked to this entity. When tracked wallets move funds on Solana, the events will appear here.
Have evidence about Drift Protocol?
3
Accepted
0
Under review
0
Rejected / revoked

Community submissions

Timeline(21 events)

2021-01-01

Drift Protocol founded by Cindy Leow, David Lu, and co-founders; V1 deployed on Solana.

Gate Learn / Crunchbase

2022-05-11

Drift V1 suffers $14.5M PnL accounting bug triggered by LUNA/UST collapse; exchange paused twice during the day.

Drift Protocol official Medium incident report

2022-05-27

Full $14.5M reimbursement made available to V1 users following emergency external financing.

Drift Protocol official Medium incident report

2022-11-04

DRIFT governance token created; Drift V2 framework initiated.

CoinGecko

2022-12-19

Drift V2 launches with JIT liquidity, decentralized order book, and passive liquidity providers.

Gate Learn

2024-10-01

Radiant Capital suffers $50M hack attributed by Mandiant to UNC4736 — the same group later attributed to the Drift exploit.

Drift Protocol / Crypto News

2024-11-09

DRIFT token reaches all-time high of $2.96.

CoinGecko

2025-11-01

OFAC issues sanctions against DPRK bankers and front companies for laundering proceeds from cybercrime and IT worker operations.

Crowell & Moring LLP client alert

2025-11-01

UNC4736 threat actors begin approaching Drift contributors at international cryptocurrency conferences, posing as representatives of a legitimate quantitative trading firm.

The Hacker News

2025-12-01

Attackers onboard an Ecosystem Vault on Drift, deposit over $1 million of real funds, and begin engaging contributors on Telegram regarding trading strategy and vault integrations.

The Hacker News

2026-03-11

Attack staging begins: 10 ETH withdrawn from Tornado Cash at approximately 09:00 Pyongyang local time.

TRM Labs

2026-03-12

Attackers deploy the CarbonVote Token (CVT) on Solana: 750 million units minted, approximately 80% attacker-controlled, seeded with $500 in real liquidity on Raydium and artificially priced at $1.00 via wash trading.

Chainalysis / TRM Labs

2026-03-23

Attackers begin preparing Solana durable nonce accounts and social engineering Security Council members into pre-signing governance transactions with hidden admin transfer authorizations.

Chainalysis

2026-03-26

Drift Security Council migrated to a new 2-of-5 threshold configuration with zero timelock, eliminating the detection delay that would otherwise have enabled intervention.

Chainalysis / Nexus Mutual

2026-04-01

At 16:05:18 UTC, pre-signed durable nonce transactions executed; admin control transferred to attacker address H7PiGqqUaanBovwKgEtreJbKmQe6dbq6VTrw6guy7ZgL. CVT listed as collateral; withdrawal limits raised to ~$500 trillion; 31 withdrawal transactions drain $285-286 million in 12 minutes ending at approximately 18:31 UTC.

Chainalysis / Elliptic / Bloomberg

2026-04-01

Within 23 minutes of admin takeover, attackers begin bridging USDC from Solana to Ethereum via Circle CCTP; $232 million bridged across 100+ transactions over eight hours. Drift halts deposits and withdrawals.

Nexus Mutual incident report / Elliptic

2026-04-05

Drift publicly states medium-high confidence attribution to UNC4736/North Korean state actors; links the attack to the same group responsible for the October 2024 Radiant Capital hack.

CoinDesk

2026-04-07

Gibbs Mura, A Law Group announces class action investigation into Drift Protocol hack losses.

BusinessWire

2026-04-14

Gibbs Mura and Joshua Joseph Law Firm LLC file class action lawsuit in federal court in Massachusetts against Circle Internet Financial, alleging aiding and abetting hackers and negligence for failure to freeze $230 million in USDC bridged via CCTP.

BusinessWire

2026-04-16

Drift Protocol and Tether announce up to $147.5 million rescue package ($127.5M from Tether, $20M from partners); Drift pivots settlement layer from USDC to USDT.

BusinessWire / CoinDesk

2026-05-05

Drift Protocol publishes comprehensive $295.4 million recovery plan: recovery tokens (1 token per $1 of verified loss, transferable), initial pool seed of $3.8 million, early redemption at discount above $5 million, estimated eight-year timeline to full compensation at current revenue rates.

CoinDesk / DL News
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-sonnet-4-20250514

generated: 4/29/2026, 8:29:48 PM

last updated: 6/14/2026, 11:15:46 PM

avoid.net — verified advice for a post-truth world