Drift Protocol hack — April 2026
Incident facts
| Date of incident | |
|---|---|
| Target type | Decentralised exchange |
| Loss | $285,000,000Published estimates range $285,000,000 to $295,000,000Price at time of incident |
| Method | Social engineeringMultisig signers manipulated into surrendering admin control, then oracles moved with a fake token |
| Chains | Solana |
| Attributed to | North Korea (Lazarus Group)Suspected |
| Outcome | Unresolved |
What happened
Drift Protocol, a derivatives exchange on Solana, lost about $285m on 1 April 2026 in under twelve minutes.
The attacker did not need a contract bug. Admin control was obtained by social-engineering the protocol's multisig signers. With a compromised admin key, a fake token was listed and its oracle price manipulated, which allowed the vaults to be drained against worthless collateral.
At the time of writing this is among the two largest incidents of 2026, alongside a $292m loss at Kelp DAO. Published figures for Drift vary between roughly $285m and $295m depending on the source and the point at which positions were valued; both bounds are recorded.
Several analysis firms have linked the attack to North Korea's Lazarus Group as part of a year in which state-linked actors accounted for the majority of stolen funds. No government has confirmed that attribution, so it is recorded here as suspected rather than established. The investigation is ongoing and this entry will change as it develops.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Drift Protocol hack — April 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/drift-protocolhttps://itokenly.com/hacks/drift-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.