Skip to content
Archive

Post

Back to deliverables

C crypto_bitlord7
Crypto Bitlord
@crypto_bitlord7

**🧵 FULL UPDATE: The $280M+ Drift Protocol Hack (April 1, 2026) – Biggest DeFi Exploit of the Year So Far** Thread: What happened, exactly how the attackers pulled it off (it’s wild), where the funds are now, and what it means for Solana DeFi. This is NOT an April Fools’ joke. Buckle up. 1/12 Drift Protocol (Solana’s leading perp DEX) got absolutely drained yesterday. On-chain data shows ~$280M–$285M yanked from the main vault address in under 12 minutes. TVL collapsed from ~$550M to ~$247M. The native $DRIFT token crashed 40%+ in hours. Deposits & withdrawals remain paused as the team works with security firms, bridges, and exchanges to contain it. 2/12 This was NOT a classic smart-contract bug, flash-loan attack, or simple private-key theft. It was a highly sophisticated, multi-week social-engineering masterpiece that weaponized Solana’s own “durable nonces” feature + a compromised 2/5 multisig. Here’s the play-by-play (confirmed by on-chain analysis + Drift’s own statements): 3/12 **Weeks of prep (the setup):** • Attacker minted ~750 million fake “CarbonVote Token” (CVT). • Dropped just $500 into a Raydium pool + wash-traded it to manufacture a fake ~$1 price history. • This fooled Drift’s oracles into thinking CVT was legit collateral. 4/12 **The social-engineering time bomb (durable nonces):** Solana lets you pre-sign transactions that can sit dormant for days/weeks before execution (durable nonces = basically a signed check you can cash later). • ~March 23: Attacker tricked TWO of Drift’s 5 Security Council multisig signers into blindly signing malicious txs (likely via transaction misrepresentation or a fake Squads page). • Those signatures sat for 9 days. 5/12 **Multisig rotation mid-attack:** • March 27: Drift rotated its Security Council to a fresh 2/5 multisig with ZERO-second timelock (big governance mistake). • Attacker adapted instantly and compromised two of the new signers too. • April 1: Right after a routine test tx, the attacker “cashed” the pre-signed nonces in two back-to-back txs (60 seconds apart). Boom — full admin control. 6/12 **The drain (12 minutes of chaos):** • Listed the fake CVT as collateral. • Disabled EVERY withdrawal guard/limit in one tx. • Deposited ~$785M worth of fake CVT “collateral.” • Drained 31 transactions across 15+ asset types (JLP, SOL, USDC, cbBTC, memecoins, you name it) straight from the vault to attacker wallet HkGz4K… • Nobody noticed for a full hour. Attacker even came back 2 hours later for a few extra million. 7/12 Funds were instantly swapped via Jupiter, converted to ETH/USDC, and some bridged to Ethereum via Circle’s CCTP. Lookonchain shows deposits to Binance + Hyperliquid + massive ETH buys. ZachXBT has been slamming Circle for not freezing the USDC fast enough. 8/12 Drift’s official response (from their X): “We are experiencing an active attack. Deposits and withdrawals have been suspended. We are coordinating with multiple security firms, bridges, and exchanges… This is not an April Fool’s joke. Updates coming.” They later confirmed the durable-nonce + unauthorized admin takeover vector. 9/12 **Current status (as of April 2):** • Protocol still frozen. • No user funds were directly stolen beyond the shared vault collateral (but the hit is massive). • Investigation ongoing — some suspect North Korean links, but unconfirmed. • $DRIFT is still bleeding. Solana DeFi TVL took a ~$1B collective hit in sympathy selling. 10/12 This exploit exposes brutal truths: • Most “DeFi” still relies on multisigs with tiny timelocks and blind signing. • Durable nonces are powerful… but deadly when combined with social engineering. • 2-of-5 with zero delay protected $280M+? That’s not decentralization. 11/12 Stay safe out there: • Revoke approvals. • Never blind-sign. • If a protocol has admin keys + no timelocks, treat it accordingly. • Watch for more freezes or recovery attempts.

@

DRIFT EXPLOIT: WHERE IS THE MONEY? The Drift Exploiter stole $278.5M from Drift through a malicious admin transfer. They moved it onto Ethereum where it now sits in 4 addresses: 0x0FE3b6908318B1F630daa5B31B49a15fC5F6B674 0xD3FEEd5DA83D8e8c449d6CB96ff1eb06ED1cF6C7 0xbDdAE987FEe930910fCC5aa403D5688fB440561B 0xAa843eD65C1f061F111B5289169731351c5e57C1

· 8K Views

1 Reposts 1 Quotes 12 Likes 4 Bookmarks
replies reposts likes
2 replies collected of 15 X reports
FateisCrypto @fateiscrypto03 ·

@crypto_bitlord7 Straight up insane and so dam interesting!

2
Hira @Hiraweb3 · 55K

@crypto_bitlord7 wild how they weaponized durable nonces like that

2