{"id":78969,"date":"2026-04-03T12:46:31","date_gmt":"2026-04-03T12:46:31","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=78969"},"modified":"2026-04-03T12:46:31","modified_gmt":"2026-04-03T12:46:31","slug":"is-your-crypto-funding-pyonyang-inside-solana-based-drift-protocol-286-million-exploit","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=78969","title":{"rendered":"Is Your Crypto Funding Pyonyang? Inside Solana-Based Drift Protocol $286 Million Exploit"},"content":{"rendered":"<div>\n<p>Blockchain analytics firm Elliptic says the $286 million exploit of Solana-based Drift Protocol is most likely linked to the Democratic People\u2019s Republic of Korea (DPRK).<\/p>\n<h2>Solana Suffered One Of The Largest Crypto Exploits In History<\/h2>\n<p>On April 1st, the DEX Drift Protocol suffered a major exploit that drained almost $300 million dollars in crypto assets from its core vaults. The exchange reported on it on its official X account as it was still undergoing:<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Drift Protocol is experiencing an active attack. Deposits and withdrawals have been suspended. We are coordinating with multiple security firms, bridges, and exchanges to contain the incident. This is not an April Fools joke. We\u2019ll provide additional updates from this account as\u2026 <a href=\"https:\/\/t.co\/03SRPq4fHj\" rel=\"nofollow\">https:\/\/t.co\/03SRPq4fHj<\/a><\/p>\n<p>\u2014 Drift (@DriftProtocol) <a href=\"https:\/\/twitter.com\/DriftProtocol\/status\/2039417136729227425?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">April 1, 2026<\/a><\/p>\n<\/blockquote>\n<p>The raid unfolded in under 20 minutes, with roughly $286 million siphoned off across a basket of assets from close to 20 vaults. Drift is the largest decentralized perpetual futures exchange on Solana. This is the biggest crypto exploit seen so far in 2026 and ranks among the largest on record, edging out the $235 million WazirX breach.<\/p>\n<p>Drift\u2019s total value lock (TVL) collapsed from roughly $550 million to under $250 million after the attack. The team\u2019s emergency response consisted of pausing deposits and withdrawals and coordinating with security firms and exchanges.<\/p>\n<p>The protocol shared the details of the incident later on, claiming it was a \u201ca highly sophisticated operation that appears to have involved multi-week preparation and staged execution\u201d. Beyond that, the exchange\u2019s official channels refrained from attributing responsibilities.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift\u2019s Security Council administrative powers.<\/p>\n<p>This was a highly sophisticated operation that appears to have involved\u2026<\/p>\n<p>\u2014 Drift (@DriftProtocol) <a href=\"https:\/\/twitter.com\/DriftProtocol\/status\/2039564437795836039?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">April 2, 2026<\/a><\/p>\n<\/blockquote>\n<p>Now, <a href=\"https:\/\/www.elliptic.co\/blog\/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack\" target=\"_blank\" rel=\"noopener nofollow\">the analytics firm Elliptic has released an investigation<\/a> claiming the on\u2011chain behavior, laundering methods, and network\u2011level indicators match the techniques seen in prior DPRK\u2011linked operations, making this not just another DeFi rug, but a suspected state\u2011sponsored attack.<\/p>\n<p>The North Korean Hackers Strike Again<\/p>\n<p>Ledger CTO Charles Guillement also linked Drift\u2019s attack method to Bybit\u2019s $1.4 billion hack, which was attributed to North Korean hacking groups. <a href=\"https:\/\/www.newsbtc.com\/news\/285m-solana-protocol-drift-largest-exploit-2026\/\" target=\"_blank\" rel=\"noopener nofollow\">NewsBTC\u2019s sister website Bitcoinist reported on this yesterday.<\/a><\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Drift Protocol, one of the leading perpetual DEXs on Solana, has been hacked for approximately $213M. This makes it the biggest hack of 2026 so far, and one of the largest ever on the Solana blockchain, right behind the Wormhole Bridge exploit of 2022.<\/p>\n<p>The full details of the\u2026<\/p>\n<p>\u2014 Charles Guillemet (@P3b7_) <a href=\"https:\/\/twitter.com\/P3b7_\/status\/2039607161328742746?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">April 2, 2026<\/a><\/p>\n<\/blockquote>\n<p>According to Elliptic, the attacker likely compromised Drift\u2019s administrator private keys, gaining privileged control over withdrawals and key parameters. The attack systematically drained three main vaults: JLP Delta Neutral, SOL Super Staking and BTC Super Staking, including a single $41.7 million JLP transfer worth about $155 million.<\/p>\n<p>Elliptic traced the stolen funds and concluded that the attacker created the wallet roughly eight days before the exploit and even received a small test transfer from a Drift vault. This suggests a pre\u2011planned, staged operation rather than a smash\u2011and\u2011grab.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-673008 size-large\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=789&amp;resize=789%2C660\" alt=\"Solana, Elliptic\" width=\"789\" height=\"660\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=2008 2008w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=502 502w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=768 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=789 789w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=1536 1536w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=750 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-03-a-las-2.20.36-p.-m.png?w=1140 1140w\" sizes=\"(max-width: 789px) 100vw, 789px\"><\/p>\n<p>After the exploit was completed, the attacker used Jupiter, a Solana DEX aggregator, to swap the stolen tokens into USDC, bridged funds to Ethereum, and then rotated into ETH and other assets across multiple wallets.<\/p>\n<p>Such cross\u2011chain laundering patterns, obfuscation methods, and network\u2011level indicators match techniques seen in prior DPRK\u2011attributed attacks, Elliptic claims. If officially confirmed, this would be the 18th such operation with over $300 million stolen already.<\/p>\n<p>Confirmed or not, there is no denying that state\u2011linked actors are systematically targeting liquidity\u2011rich crypto protocols to fund North Korea\u2019s weapons programs. Let\u2019s not forget that <a href=\"https:\/\/bitcoinist.com\/crypto-north-korea-linked-lazarus-group-2023-losses\/\" target=\"_blank\" rel=\"noopener \">the North Korea\u2011affiliated Lazarus Group<\/a>\u00a0has funneled billions of dollars in stolen money through cryptocurrency networks.<\/p>\n<p>Elliptic has already clustered all attacker\u2011linked token accounts on Solana and Ethereum so exchanges and protocols can screen against contaminated funds in near real time.<\/p>\n<p>The hack will likely harden scrutiny of Solana DeFi governance, admin key design, and multisig security, even as the ecosystem continues to chase institutional\u2011grade perps liquidity.<\/p>\n<p><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" class=\"aligncenter wp-image-673011 size-large\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=980&amp;resize=980%2C592\" alt=\"Solana, SOL, SOLUSD\" width=\"980\" height=\"592\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=2770 2770w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=640 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=768 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=980 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=1536 1536w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=2048 2048w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=750 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2026\/04\/SOLUSD_2026-04-03_14-30-06.png?w=1140 1140w\" sizes=\"auto, (max-width: 980px) 100vw, 980px\"><\/p>\n<p>Cover image from Perplexity. SOLUSD chart from Tradingview.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Blockchain analytics firm Elliptic says the $286 million exploit of Solana-based Drift Protocol is most likely linked to the Democratic People\u2019s Republic of Korea (DPRK). Solana Suffered One Of The Largest Crypto Exploits In History On April 1st, the DEX Drift Protocol suffered a major exploit that drained almost $300 million dollars in crypto assets [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-78969","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/78969","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=78969"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/78969\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=78969"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=78969"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=78969"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}