Skip to content
Archive

Post

Back to @zachxbt

Z zachxbt
ZachXBT
@zachxbt

3/ On April 1, 2026, Drift Protocol was exploited for $280M. The exploiter used CCTP to bridge 232M+ USDC from Solana to Ethereum across 100+ transactions over six consecutive hours. 10+ additional DeFi protocols across the Solana ecosystem were indirectly impacted. Despite the attacker laundering funds over six consecutive hours across Circle's own native bridge, no USDC was frozen. The attacker has been linked to DPRK by Elliptic. Theft address: HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES

@

Update: $230M+ USDC bridged via CCTP from Solana to Ethereum across 100+ txns. 6 hours is how long Circle had to freeze stolen funds from the $280M+ Drift hack. Circle is a centralized stablecoin issuer headquartered in New York and the attack began around 12 pm ET. Why does our industry allow them to stay silent? @jerallaire @circle @usdc

· 114K Views

19 Reposts 8 Quotes 557 Likes 24 Bookmarks
replies reposts likes
9 replies collected of 15 X reports
ZachXBT @zachxbt · 1.1M

4/ On January 25, 2026, SwapNet was exploited for $16M. 3M USDC sat in the exploiter's address for two days. Both law enforcement and private sector experts submitted temporary freeze requests to Circle for the theft address. Both were unsuccessful. One victim pursued a New York court order. The funds were swapped hours before the TRO was granted. Theft address: 0x6cAad74121bF602e71386505A4687f310e0D833e

3 372
logan @logantoday ·

@zachxbt Abaolutely insane the lack of response to allow terrorists to assume funds

2 4
Chronos @chrono_sss ·

@zachxbt 100+ transactions over 6 hours through their own bridge and circle couldn't be bothered to flip a switch, DPRK literally used the compliance infrastructure as the getaway car

Brother Sefirot 𒉭🥷🏼 @SefirotWatch ·

@zachxbt They don't give a single fuck Crime szn full on. x.com/SefirotWatch/status/2040…

1
ghostbladexyz @ghostbladexyz ·

@zachxbt least funny April Fool's 💀

Agentic Bro @AgenticBro11 ·

Critical thread 🔍 ZachXBT's investigation shows exactly why pre-investment due diligence matters. Protocol-level hacks like Drift are devastating, but individual scams are equally dangerous: • Fake "support" accounts • Phishing Telegram channels • Rug pull token contracts AgenticBro helps you scan all three before you engage. Free protection: t.me/agenticbro $AGNTCBRO #CryptoSecurity #DeFiSafety

Marcus Reid | DeFi & Regulation @0xMarcusReid ·

@zachxbt ZachXBT's data shows 232M+ USDC moved via CCTP over 6 hours with zero intervention from Circle. This raises serious questions about stablecoin issuers' responsibility to monitor and freeze illicit funds on their bridges.

The AI Therapist @TheAIShrink ·

@zachxbt $280M. the audit said it was fine.

1
tyler malin @tylermalin ·

The core issue is not “centralized stablecoin bad” or “Circle must freeze everything instantly.” The issue is governance contradiction. If USDC has a blacklist/freeze function, markets deserve clear rules for when it will be used, who can trigger it, what evidence threshold applies, and how emergency requests are handled. Circle cannot market regulated trust while treating freeze authority as discretionary, opaque, and slow in exactly the moments where regulated trust is supposed to matter. The Drift facts are especially hard to ignore: roughly $285M stolen, with more than $230M USDC allegedly bridged through CCTP over about six hours, and multiple analytics firms tying the attack to DPRK-linked activity. Elliptic and TRM both reported suspected DPRK indicators. (Elliptic📷) So the policy question is simple: If a regulated issuer has technical control, legal authority under its terms, and real-time visibility into its own bridge, what duty does it owe during an active laundering event? Either USDC is neutral infrastructure, in which case the freeze function should be narrowly constrained by law. Or USDC is regulated financial infrastructure, in which case emergency response standards, escalation pathways, and accountability should be explicit. The worst answer is the current gray zone: centralized control when convenient, decentralization rhetoric when users need protection.