Signal

Solana-based Drift protocol suffers $285 million exploit in largest 2026 DeFi hack

Evidence first: scan the strongest sources, then decide whether to go deeper.

redditrsstelegram
cryptodefisolanasecurityexploitdex
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
limited source diversity in top sources
Overview

On April 1, 2026, the Solana-based decentralized exchange Drift Protocol was hit by a sophisticated cyberattack that drained approximately $285 million in multiple crypto assets.

Entities
Drift ProtocolDRIFTUSDCUSDTWBTCWETH
Score total
2.48
Momentum 24h
11
Posts
11
Origins
7
Source types
3
Duplicate ratio
18%
Why now
  • The exploit is the largest crypto hack of 2026, occurring just days ago, impacting Solana DeFi ecosystem.
  • Drift’s response and outreach to stolen fund holders on Ethereum show active efforts to mitigate damage.
  • Raises urgent questions about multisig security and Solana protocol features needing review to prevent future attacks.
Why it matters
  • Highlights critical governance and security vulnerabilities in DeFi protocols using multisig and durable nonce features.
  • Demonstrates ongoing risks of sophisticated social engineering attacks in crypto, impacting user funds and trust.
  • Links to geopolitical risks with suspected North Korea hacker involvement, emphasizing need for robust security measures.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • Drift Protocol lost approximately $285 million in a sophisticated exploit involving durable nonce social engineering on Solana.
  • The attack compromised multisig governance and administrative powers, raising concerns about DeFi security and governance vulnerabilities.
  • Drift has reached out to wallets holding stolen funds on Ethereum and linked the attack to North Korea-associated hackers.
How sources frame it
  • Decrypt: neutral
  • The Hacker News: neutral
  • PYMNTS: neutral
All evidence
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 0
Top publishers (this list)
  • DecryptNews (1)
  • solana (1)
  • CryptoMarkets (1)
  • NewsBTC (1)
  • The Hacker News (1)
  • CryptoCurrency (1)
Top origin domains (this list)
  • decrypt.co (1)
  • reddit.com (1)
  • realnarrativenews.com (1)
  • newsbtc.com (1)
  • thehackernews.com (1)
  • cybernews.com (1)