Crypto platform Drift Protocol has been drained of $280 million in a highly sophisticated heist, with security analysts already tying North Korea’s elite hacking units to the hit.
Posting initial details of the April 1st robbery to X, Drift said that the threat actors had gained access through a novel attack involving durable nonces, essentially reusing one‑time codes that were supposed to be temporary, “resulting in a rapid takeover of Drift’s Security Council administrative powers”.
Drift Protocol, a trading platform built on the Solana blockchain where users can make long‑term bets on crypto without actually owning the coins, said that the operation was not the result of a bug in its programmes or smart contracts, and that there was no evidence of compromised seed phrases.
Instead, they manipulated Drift’s approval process, using social engineering to trick multisig signers, those who control the protocol, into providing pre-signed authorisations, allowing the hackers to execute a malicious admin transfer and gain control of protocol-level permissions.
According to Drift, the attackers then used those permissions to whitelist a ‘malicious asset’ with only a few thousand dollars of real liquidity, then pumped its internal price until the system accepted it as legitimate collateral worth hundreds of millions.
Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers.
This was a highly sophisticated operation that appears to have involved…
— Drift (@DriftProtocol) April 2, 2026
Investigating the incident, researchers at blockchain intelligence outfit TRM Labs said the heist appeared to involve weeks of preparation and staged execution, and required infrastructure, token manufacturing, and social engineering to run in coordination.
According to TRM, Drift was stripped of $285 million in user assets in just 12 minutes, with most of the stolen funds being bridged to Ethereum within hours.
“The confidence of the hackers was staggering. Each bridging transaction moved hundreds of thousands or, more often, millions in USDC, far outstripping the speed and aggressiveness of even the Bybit laundering of 2025,” wrote the researchers.
Recommended reading
- North Korea Stole $659M in Crypto Last Year, Says US
- Major Banks Hit by Vendor Cyber-attack
- North Korean Fake IT Workers Targeting European Firms
In the aftermath, both TRM Labs and blockchain analytics firm Elliptic have pointed the blame for the crypto robbery at North Korea, with TRM claiming to have identified several on-chain indicators aligning with known DPRK tradecraft, such as the use of Tornado Cash for staging and cross-chain bridging patterns.
Likewise, Elliptic said that on-chain behaviour, laundering methods and network-level indicators were consistent with North Korean operations. This incident, if confirmed to be the DPRK, represents the eighteenth North Korean crypto theft Elliptic has tracked this year, adding up to over $300 million stolen.
While Drift Protocol said that it is working with security firms, exchanges, bridges and law enforcement to trace and freeze the stolen crypto, its users have been hounding the platform for more information on when they might see their funds returned.





