Fact-check findings
What an automated fact-checker found when it re-read Drift Protocol against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
10 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #4[disputed][awaiting moderator]in section: Protocol Overview
“The protocol's native governance token (DRIFT) launched on a date aligned with the V2 deployment”
reviewerThe DRIFT governance token launched on a date aligned with the V2 deployment (i.e., around December 2022)Multiple sources place the DRIFT token's Token Generation Event on May 16, 2024, roughly 17 months after V2 launched, contradicting the page's claim of alignment with the V2 deployment.Proposed correction (not yet applied)The protocol's native governance token (DRIFT) launched via a Token Generation Event on May 16, 2024, roughly a year and a half after the V2 deployment - #5[disputed][awaiting moderator]in the timeline
“2022-11-04”
reviewerDRIFT governance token created 2022-11-04Timeline date is off by roughly 18 months relative to the DRIFT token's actual Token Generation Event.Proposed correction (not yet applied)2024-05-16 - #6[disputed][awaiting moderator]in the timeline
“DRIFT governance token created; Drift V2 framework initiated.”
reviewerTimeline event describing DRIFT token creation and V2 framework initiation on 2022-11-04Event text conflates two unrelated milestones and misdates the token's actual creation.Proposed correction (not yet applied)DRIFT governance token created via Token Generation Event (TGE) and initial airdrop. - #7[disputed][awaiting moderator]in section: Protocol Overview
“reached an all-time high of $2.96 on November 9, 2024”
reviewerDRIFT token reached an all-time high of $2.96 on November 9, 2024The page's own cited source (CoinGecko) does not support the $2.96/Nov 9 figures; other trackers (Coinbase $2.96, CoinLore $2.65) vary, but the specifically cited source contradicts the page.Proposed correction (not yet applied)reached an all-time high of $2.60 on November 8, 2024 - #8[disputed][awaiting moderator]in the timeline
“2024-11-09”
reviewerTimeline: DRIFT token reaches all-time high of $2.96 on 2024-11-09Date field disputed against the cited source itself.Proposed correction (not yet applied)2024-11-08 - #9[disputed][awaiting moderator]in the timeline
“DRIFT token reaches all-time high of $2.96.”
reviewerTimeline event text: DRIFT token reaches all-time high of $2.96Value disputed against the cited source itself.Proposed correction (not yet applied)DRIFT token reaches all-time high of $2.60. - #13[disputed][awaiting moderator]in section: April 2026 Exploit: $285 Million Theft
“Approximately $285–286 million in user assets were drained in roughly 12 minutes, between 16:05 UTC and 18:31 UTC.”
reviewerApproximately $285-286 million was drained in roughly 12 minutes, between 16:05 UTC and 18:31 UTCThe page attaches the 'roughly 12 minutes' figure directly to the 16:05-18:31 UTC window, but that window spans about 2.5 hours; sources indicate 12 minutes describes only the initial burst of withdrawal transactions within that longer window.Proposed correction (not yet applied)Approximately $285–286 million in user assets were drained beginning at 16:05 UTC, with the bulk of the 31 withdrawal transactions completed within roughly 12 minutes and on-chain drainage continuing until approximately 18:31 UTC. - #14[disputed][awaiting moderator]in the timeline
“31 withdrawal transactions drain $285-286 million in 12 minutes ending at approximately 18:31 UTC.”
reviewerTimeline: 31 withdrawal transactions drain $285-286 million in 12 minutes ending at approximately 18:31 UTCSame underlying error as the section 2 finding.Proposed correction (not yet applied)31 withdrawal transactions drain $285-286 million, with the bulk completed within roughly 12 minutes and on-chain drainage continuing until approximately 18:31 UTC. - #21[disputed][awaiting moderator]in the timeline
“2024-10-01”
reviewerTimeline: Radiant Capital hack occurred 2024-10-01The precise date_original field defaults to the first of the month rather than the actual, well-documented exploit date of October 16, 2024.Proposed correction (not yet applied)2024-10-16 - #26[disputed][awaiting moderator]in the timeline
“2025-11-01”
reviewerTimeline: OFAC sanctions action occurred 2025-11-01The date_original field defaults to the first of the month rather than the documented announcement date of November 4, 2025.Proposed correction (not yet applied)2025-11-04
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #28[unverifiable][awaiting moderator]in section: Class Action Litigation
“Lead plaintiff Joshua McCollum, a Missouri resident, had approximately $23,500 in assets affected by the hack.”
reviewerLead plaintiff Joshua McCollum, a Missouri resident, had approximately $23,500 in assets affected by the hackCould not independently confirm the specific $23,500 loss figure or Missouri residency from any secondary source consulted; this level of detail may only appear in the underlying court complaint, which was not directly accessible.
stale
2 claimsThe claim was accurate when written but events since have overtaken it.
- #32[stale][awaiting moderator]in the summary
“which constituted the largest DeFi hack of 2026”
reviewerDrift Protocol's April 2026 exploit constituted the largest DeFi hack of 2026True at the time of the April 1 hack, but this claim is not updated to reflect that the KelpDAO exploit 17 days later was slightly larger, superseding Drift's 'largest of 2026' status. The page's own Ecosystem Contagion section (sections[8]) correctly lists KelpDAO at $293M vs Drift's $285M, creating an internal inconsistency with the summary and the exploit section heading/lead.Proposed correction (not yet applied)which was the largest DeFi hack of 2026 at the time, a distinction later surpassed by the $292–293 million KelpDAO exploit on April 18, 2026 - #33[stale][awaiting moderator]in section: April 2026 Exploit: $285 Million Theft
“Drift Protocol suffered the largest DeFi hack of 2026”
reviewerOn April 1, 2026, Drift Protocol suffered the largest DeFi hack of 2026Same underlying staleness as the summary claim; the page's own later section acknowledges KelpDAO's larger figure.Proposed correction (not yet applied)Drift Protocol suffered what was at the time the largest DeFi hack of 2026 (a distinction later surpassed by the $292–293 million KelpDAO exploit on April 18, 2026)
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #17[partially supported][awaiting moderator]in section: April 2026 Exploit: $285 Million Theft
“On March 26–27, 2026, Drift migrated its Security Council to a new 2-of-5 threshold configuration with zero timelock, eliminating the detection delay that would otherwise have enabled intervention.”
reviewerOn March 26-27, 2026, Drift migrated its Security Council to a 2-of-5 threshold with zero timelockMinor internal inconsistency: this section states a two-day range while the page's own timeline entry and the cited source both use a single date. - #31[partially supported][awaiting moderator]in section: Ecosystem Contagion and Broader Impact
“Solana DeFi TVL dropped approximately 12% from roughly $8.1 billion to $5.7 billion in the days following the attack.”
reviewerSolana DeFi TVL dropped approximately 12% from roughly $8.1 billion to $5.7 billion in the days following the attackThe general direction and rough magnitude (roughly 12% decline) is corroborated, but the specific absolute dollar figures ($8.1B and $5.7B) could not be independently confirmed from the sources consulted.
confirmed
22 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“founded in 2021 by Cindy Leow, David Lu, and co-founders”
reviewerDrift Protocol was founded in 2021 by Cindy Leow, David Lu, and co-foundersMultiple independent sources corroborate the 2021 founding and named co-founders. - #2[confirmed][no action needed]in section: Protocol Overview
“The protocol operates under Drift Labs and is headquartered in Australia.”
reviewerDrift operates under Drift Labs and is headquartered in AustraliaCorroborated by independent secondary sources (Sydney, Australia), though not deeply sourced by the page's cited Gate Learn article specifically. - #3[confirmed][no action needed]in section: Protocol Overview
“Drift V2 launched on December 19, 2022, introducing Just-in-Time (JIT) liquidity, a decentralized order book, and passive liquidity providers.”
reviewerDrift V2 launched on December 19, 2022 with JIT liquidity, decentralized order book, and passive LPsDate and feature description independently confirmed. - #10[confirmed][no action needed]in section: Protocol Overview
“Prior to the April 2026 exploit, DeFiLlama listed Drift with approximately $311–550 million in total value locked, making it one of the largest Solana-based DeFi protocols.”
reviewerPrior to the exploit, DeFiLlama listed Drift with approximately $311-550 million TVL, one of the largest Solana DeFi protocolsThe $550M pre-hack TVL figure is corroborated; the $311M figure likely reflects an earlier snapshot within the stated range. - #11[confirmed][no action needed]in section: 2022 Security Incident: $14.5M PnL Accounting Bug
“On May 11, 2022, Drift Protocol V1 suffered a critical security incident stemming from a PnL accounting bug that was exacerbated by extreme market volatility during the LUNA/UST collapse.”
reviewerOn May 11, 2022, Drift V1 suffered a PnL accounting bug exacerbated by the LUNA/UST collapseSingle-sourced to the official incident report, which is appropriate given this is a first-party technical postmortem; no contradicting sources found. - #12[confirmed][no action needed]in section: 2022 Security Incident: $14.5M PnL Accounting Bug
“All affected users were fully reimbursed, and Drift increased its bug bounty from $500,000 to $1 million.”
reviewerAll affected users were fully reimbursed and Drift raised its bug bounty from $500,000 to $1 millionNo independent secondary source found disputing this, consistent with the single official source. - #15[confirmed][no action needed]in section: April 2026 Exploit: $285 Million Theft
“The attack was the culmination of a six-month social engineering and malware operation attributed with medium-high confidence to UNC4736, a North Korean state-sponsored threat actor.”
reviewerThe attack was the culmination of a six-month social engineering and malware operation attributed with medium-high confidence to UNC4736Well corroborated across multiple tier-1 blockchain forensics firms and news outlets. - #16[confirmed][no action needed]in section: April 2026 Exploit: $285 Million Theft
“On March 12, 2026, the attackers deployed the CarbonVote Token (CVT), a fictitious Solana asset with a total supply of 750 million units (approximately 80% attacker-controlled), seeded with roughly $500 in real liquidity on Raydium and artificially priced at $1.00 via wash trading and a controlled price oracle.”
reviewerAttackers deployed the CarbonVote Token (CVT) on March 12, 2026: 750M supply, ~80% attacker-controlled, seeded with ~$500 real liquidity, priced at $1.00 via wash tradingPrecisely confirmed against the primary cited source. - #18[confirmed][no action needed]in section: April 2026 Exploit: $285 Million Theft
“Approximately $232 million in USDC was bridged to Ethereum across 100+ transactions over an eight-hour window, then converted to ETH and dispersed.”
reviewerApproximately $232 million in USDC was bridged to Ethereum via CCTP across 100+ transactions over an eight-hour windowFigure and mechanism corroborated across multiple sources, including the class-action complaint's own allegations. - #19[confirmed][no action needed]in section: April 2026 Exploit: $285 Million Theft
“The largest single asset extracted was JLP tokens ($155.6 million, approximately 41.7 million units).”
reviewerThe largest single asset extracted was JLP tokens ($155.6 million, approximately 41.7 million units)Figure matches Elliptic closely; Chainalysis reports a marginally higher figure, a normal degree of cross-firm variance in forensic estimates. - #20[confirmed][no action needed]in section: DPRK/Lazarus Group Attribution
“The connection to the October 2024 Radiant Capital exploit ($50 million stolen via similar social engineering and malware delivery) was confirmed at medium-high confidence by Drift based on both on-chain fund flow overlaps and operational persona similarities.”
reviewerThe October 2024 Radiant Capital exploit ($50 million) was confirmed by Drift as connected to the same threat actor at medium-high confidenceAmount and attribution well corroborated; see separate finding on the imprecise timeline date for this event. - #22[confirmed][no action needed]in section: DPRK/Lazarus Group Attribution
“Elliptic independently noted that the attack is consistent with techniques observed in previous DPRK-attributed incidents and identified it as the 18th DPRK-linked crypto incident tracked in 2026.”
reviewerElliptic identified the Drift attack as the 18th DPRK-linked crypto incident tracked in 2026Directly confirmed against the primary source. - #23[confirmed][no action needed]in section: DPRK/Lazarus Group Attribution
“TRM Labs further noted that DPRK-linked operations accounted for 76% of all 2026 crypto hack losses through April, totaling $577 million of $759 million stolen ecosystem-wide.”
reviewerTRM Labs: DPRK-linked operations accounted for 76% of all 2026 crypto hack losses through April, totaling $577 million of $759 million stolen ecosystem-wideFigures are internally consistent and match TRM Labs reporting. - #24[confirmed][no action needed]in section: DPRK/Lazarus Group Attribution
“Since 2017, DPRK-linked operations have cumulatively stolen an estimated $6 billion in cryptocurrency, with proceeds assessed by the UN Panel of Experts to fund the regime's ballistic missile and nuclear weapons programs.”
reviewerSince 2017, DPRK-linked operations have cumulatively stolen an estimated $6 billion in cryptocurrencyFigure matches current TRM Labs reporting. - #25[confirmed][no action needed]in section: DPRK/Lazarus Group Attribution
“OFAC issued related sanctions against DPRK bankers and front companies involved in laundering cryptocurrency proceeds as recently as November 2025.”
reviewerOFAC issued sanctions against DPRK bankers and front companies for laundering cryptocurrency proceeds as recently as November 2025General claim confirmed; see separate finding on the imprecise timeline date_original field for this event. - #27[confirmed][no action needed]in section: Class Action Litigation
“On April 14, 2026, law firm Gibbs Mura, A Law Group (in association with Joshua Joseph Law Firm LLC) filed a class action lawsuit in federal court in Massachusetts on behalf of Drift Protocol investors who sustained losses in the April 1, 2026 exploit.”
reviewerOn April 14, 2026, Gibbs Mura (with Joshua Joseph Law Firm LLC) filed a class action against Circle Internet Financial in federal court in MassachusettsFiling date, parties, and venue are corroborated across multiple outlets. - #29[confirmed][no action needed]in section: Recovery Plan and User Impact
“On April 16, 2026, Drift Protocol announced a $147.5 million rescue package led by Tether, comprising up to $127.5 million from Tether (contingent on performance benchmarks, structured as a $100 million revenue-linked credit facility, an ecosystem grant, and loans to market makers) and $20 million from other unspecified partners.”
reviewerOn April 16, 2026, Drift announced a $147.5 million rescue package led by Tether ($127.5M Tether + $20M partners)Figures and structure corroborated across CoinDesk, BusinessWire, and other outlets. - #30[confirmed][no action needed]in section: Recovery Plan and User Impact
“The recovery pool was seeded with approximately $3.8 million in remaining protocol resources.”
reviewerThe recovery pool was seeded with approximately $3.8 million in remaining protocol resources, with total verified losses of approximately $295.4 millionPrecisely matches CoinDesk's reporting on the recovery plan. - #34[confirmed][no action needed]in section: Ecosystem Contagion and Broader Impact
“The Drift attack was also the second-largest exploit in Solana ecosystem history, following the $326 million Wormhole bridge hack of February 2022.”
reviewerThe Drift attack was the second-largest exploit in Solana ecosystem history, following the $326 million Wormhole bridge hack of February 2022This ranking is specific to the Solana ecosystem (as opposed to 'largest DeFi hack of 2026' generally) and remains accurate since the April 18 KelpDAO exploit was not a Solana-native protocol. - #35[confirmed][no action needed]in section: Ecosystem Contagion and Broader Impact
“The Solana-based yield protocol Carrot permanently shut down, becoming one of the first DeFi protocol casualties of the Drift exploit's contagion.”
reviewerThe Solana-based yield protocol Carrot permanently shut down, becoming one of the first DeFi protocol casualties of the Drift exploit's contagionDirectly corroborated. - #36[confirmed][no action needed]in section: Ecosystem Contagion and Broader Impact
“DeFiLlama confirmed April 2026 as the worst month for crypto hacks in recorded history, with approximately 28–30 incidents totaling over $625–651 million stolen.”
reviewerDeFiLlama confirmed April 2026 as the worst month for crypto hacks in recorded history, with approximately 28-30 incidents totaling over $625-651 millionThe 'worst month in recorded history' framing is by incident count; by dollar amount, February 2025 (Bybit, ~$1.4B) was larger. The page's phrasing mirrors its cited lower-tier source (credibility 3) rather than clarifying this nuance, but the underlying incident-count and dollar-range figures are corroborated by tier-1/2 sources. - #37[confirmed][no action needed]in section: Ecosystem Contagion and Broader Impact
“The Drift exploit ($285 million, April 1) and the KelpDAO exploit ($293 million, April 18) together accounted for approximately 89% of April's total losses.”
reviewerThe Drift exploit ($285 million) and KelpDAO exploit ($293 million, April 18) together accounted for approximately 89% of April's total lossesCorroborated, and notably this section correctly identifies KelpDAO's $293M figure as exceeding Drift's $285M, which is inconsistent with the 'largest DeFi hack of 2026' framing used elsewhere on the page (see related stale findings).