Summary
Drift Protocol is a decentralized perpetual futures exchange built on the Solana blockchain, founded in 2021 by Cindy Leow, David Lu, and co-founders. The protocol has experienced two significant security incidents: a $14.5 million PnL accounting bug in May 2022 triggered by the LUNA collapse (fully reimbursed), and a catastrophic $285–286 million exploit on April 1, 2026, attributed with medium-high confidence to the North Korean state-sponsored threat actor UNC4736 (also tracked as Lazarus Group, AppleJeus, and Citrine Sleet), which constituted the largest DeFi hack of 2026. A $295 million recovery plan involving Tether-led financing and user-issued recovery tokens was announced in May 2026; a class action lawsuit was simultaneously filed against Circle Internet Financial.
Connected Entities
22 entities · 3 linked investigations- Drift Staked SOL (dSOL)→associated with→Drift(80%)
- + 37 more
Connected Through
3 shared actors · 3 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- ◇Sanctum Marketswalletalso inBonk·45
- ⌂Drift Protocolprotocolalso inDrift Protocol·18
- ◇H7PiGq…7ZgLwalletalso inCarbonVote Token·0
Live On-Chain Activity
1 address watched · via HeliusCommunity submissions
“Elliptic Tier 1 post-mortem formally attributing the $286M April 1 2026 Drift Protocol exploit to DPRK actors; corroborated independently by Chainalysis and TRM Labs”
— avoid-scout
“TRM Labs confirms $285M Drift Protocol exploit April 1, 2026 with medium-confidence DPRK/UNC4736 attribution; six-month social engineering operation; fictitious collateral oracle manipulation”
— avoid-scout
“May 5, 2026 CoinDesk report on Drift's post-exploit recovery plan confirms DPRK attribution, quantifies total verified losses at ~$295M, details attacker wallet tracking status, and shows community controversy over victim compensation structure.”
— avoid-scout
Timeline(21 events)
2021-01-01
Drift Protocol founded by Cindy Leow, David Lu, and co-founders; V1 deployed on Solana.
Gate Learn / Crunchbase2022-05-11
Drift V1 suffers $14.5M PnL accounting bug triggered by LUNA/UST collapse; exchange paused twice during the day.
Drift Protocol official Medium incident report2022-05-27
Full $14.5M reimbursement made available to V1 users following emergency external financing.
Drift Protocol official Medium incident report2022-12-19
Drift V2 launches with JIT liquidity, decentralized order book, and passive liquidity providers.
Gate Learn2024-10-01
Radiant Capital suffers $50M hack attributed by Mandiant to UNC4736 — the same group later attributed to the Drift exploit.
Drift Protocol / Crypto News2025-11-01
OFAC issues sanctions against DPRK bankers and front companies for laundering proceeds from cybercrime and IT worker operations.
Crowell & Moring LLP client alert2025-11-01
UNC4736 threat actors begin approaching Drift contributors at international cryptocurrency conferences, posing as representatives of a legitimate quantitative trading firm.
The Hacker News2025-12-01
Attackers onboard an Ecosystem Vault on Drift, deposit over $1 million of real funds, and begin engaging contributors on Telegram regarding trading strategy and vault integrations.
The Hacker News2026-03-11
Attack staging begins: 10 ETH withdrawn from Tornado Cash at approximately 09:00 Pyongyang local time.
TRM Labs2026-03-12
Attackers deploy the CarbonVote Token (CVT) on Solana: 750 million units minted, approximately 80% attacker-controlled, seeded with $500 in real liquidity on Raydium and artificially priced at $1.00 via wash trading.
Chainalysis / TRM Labs2026-03-23
Attackers begin preparing Solana durable nonce accounts and social engineering Security Council members into pre-signing governance transactions with hidden admin transfer authorizations.
Chainalysis2026-03-26
Drift Security Council migrated to a new 2-of-5 threshold configuration with zero timelock, eliminating the detection delay that would otherwise have enabled intervention.
Chainalysis / Nexus Mutual2026-04-01
At 16:05:18 UTC, pre-signed durable nonce transactions executed; admin control transferred to attacker address H7PiGqqUaanBovwKgEtreJbKmQe6dbq6VTrw6guy7ZgL. CVT listed as collateral; withdrawal limits raised to ~$500 trillion; 31 withdrawal transactions drain $285-286 million in 12 minutes ending at approximately 18:31 UTC.
Chainalysis / Elliptic / Bloomberg2026-04-01
Within 23 minutes of admin takeover, attackers begin bridging USDC from Solana to Ethereum via Circle CCTP; $232 million bridged across 100+ transactions over eight hours. Drift halts deposits and withdrawals.
Nexus Mutual incident report / Elliptic2026-04-05
Drift publicly states medium-high confidence attribution to UNC4736/North Korean state actors; links the attack to the same group responsible for the October 2024 Radiant Capital hack.
CoinDesk2026-04-07
Gibbs Mura, A Law Group announces class action investigation into Drift Protocol hack losses.
BusinessWire2026-04-14
Gibbs Mura and Joshua Joseph Law Firm LLC file class action lawsuit in federal court in Massachusetts against Circle Internet Financial, alleging aiding and abetting hackers and negligence for failure to freeze $230 million in USDC bridged via CCTP.
BusinessWire2026-04-16
Drift Protocol and Tether announce up to $147.5 million rescue package ($127.5M from Tether, $20M from partners); Drift pivots settlement layer from USDC to USDT.
BusinessWire / CoinDesk2026-05-05
Drift Protocol publishes comprehensive $295.4 million recovery plan: recovery tokens (1 token per $1 of verified loss, transferable), initial pool seed of $3.8 million, early redemption at discount above $5 million, estimated eight-year timeline to full compensation at current revenue rates.
CoinDesk / DL NewsDecision Log
- hash: B7Lrr5v8AHCfEXZYBjVHcoJtaDseF7CA1z6AmK1FmeVQ
- hash: 3s9cA6cF7L33HDdTKFkpL1P1uNikAjmmxedbuzVn8mdc
- hash: 4XCUy7W5aMFgxSoDCvP6nqoigqSas1h2eXmALj4GVQ3a
- hash: 6VPivrTUkWyKYv94EEg4o8f62fXuETQtPVnw18GEzvED
- hash: 47S8WJ127FyuBdXLvyHsjmNSZrUmFXVxrgtpS1QgmiQz
- hash: 4seEZDn8Q3QBikVdxb9rduqUwqdDfcCA7xepDvjFapGQ
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-20250514
generated: 4/29/2026, 8:29:48 PM
last updated: 6/14/2026, 11:15:46 PM
avoid.net — verified advice for a post-truth world