Cryptopolitan
January 4, 2026 6:53 PM UTC

Drift Protocol suffered an ongoing attack against all its vaults, with over $270M feared stolen within an hour

Drift Protocol shows on-chain data of suspicious transactions of around $200M. The latest Web3 attack arrives after several slow weeks with smaller exploits. Solana on-chain data showed large-scale outflows from Drift Protocol, one of the leading decentralized exchanges on Solana. The losses spanned multiple tokens, for an estimated loss of over $200M. Solana influencer Mert Mumtaz noticed the exploit, calling for further research and possible cooperation in intercepting the assets. hello someone from circle reach out asap, seeing high likelihood of a potentially large exploit — mert (@mert) April 1, 2026 Since Drift Protocol is a DEX, multiple assets may be affected. About an hour after the attack, Drift Protocol had lost nearly 50% of its liquidity, or around $270M . What caused the Drift Protocol loss? The exploit was intercepted within the first hour, showing a series of suspicious transactions. The latest transfer was for 10,000 SOL sent to a new wallet . Drift protocol confirmed the exploit, calling users not to deposit funds and to stop trading. The team did not explain how it would stop the attack, but for now, Phantom Wallet has stopped access to the protocol. We are observing unusual activity on the protocol. We are currently investigating. Please do not deposit funds into the protocol while we investigate. This is not an April Fools joke. Proceed with caution until further notice. We’ll provide additional updates from this account. — Drift (@DriftProtocol) April 1, 2026 The losses came in a series of transactions originating from a single Drift Protocol account, potentially signaling that a user had full control of assets. The outgoing transactions included SOL, JitoSOL, WETH, FARTCOIN, USDC, SyrupUSDC, and other assets. Some of the stolen assets, like cbBTC, may be frozen by the issuer if intercepted on time before swapping. The attack was ongoing, constantly adding new assets supported by Drift, including JLP, over $2M in mSOL, INF, dSOL, and other tokens. The exploiter also took a little over 282 BTC and minted a new token to taunt Drift Protocol. Some of the funds were sent to ChainFlip and swapped into USDC, a token that could hypothetically be frozen if Circle reacted on time. Some of the funds were sent to Ethereum wallets , potentially ready to be mixed and obscure their tracks. Funds are also moving to Raydium, Orca, Meteora, and other intermediary wallets. Drift Protocol may be the biggest Web3 attack of this crypto cycle The DEX hack is even bigger than the $60M exploit of Cetus Protocol in the summer of 2025. Cetus Protocol ended up losing over $223M. Before the exploit, Drift Protocol held over $550M in total value locked, becoming an attractive target for Web3 hackers. The protocol also carried nearly $70M in daily perpetual futures trading. The attack has the potential to become the most serious Web3 event in the past two years, surpassing other similar exploits. The exploit follows the usual practice of moving and swapping assets quickly, instead of leaving them in intermediary wallets. The exploiter was prepared eight days before the exploit, using multiple Web3 assets, including the Wormhole bridge. so, drift protocol vault was drained and I found some interesting things onchain: drainer [ HkG…ZES ] was funded 8 days ago via near intents, but was inactive and suddenly received huge amounts from drift vault (a) drainer transferred/swapped the amount to launderer [… pic.twitter.com/aheY3PHx3t — aryan | 🐂 (@_0xaryan) April 1, 2026 The attack targeted Solana just as it emerged as the leading DEX destination for token trading and perpetual futures. The event also resolved a Polymarket pair predicting another large-scale crypto hack above $100M by the end of the year. After the hack, the protocol turned out to lack a Certik audit and to have some governance vulnerabilities. While the audit is not a guarantee, it may remove obvious exploit points. On-chain researchers noticed a test transaction a week before the true exploit, signaling the attacker was aware of the protocol’s weak points. Drift Protocol’s native DRIFT token fell by 10% in the first hours after the hack, down to $0.059. The attacker controls 2.5% of the FARTCOIN supply and may also crash the price of other assets. The wrapped BTC and ETH may also cause disparities with the main asset, affecting other protocols as well. Despite the slower Web3 activity, protocols remain attractive for exploits, with multiple techniques, including supply chain attacks. This time, researchers noted the hacker gained admin access and essentially locked out Drift Protocol by changing the admin keys, making it impossible to stop the attack that drained multiple pools. If you want a calmer entry point into DeFi crypto without the usual hype, start with this free video.

ChartModo Newsletter
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.