{"id":10982,"date":"2026-04-03T18:13:09","date_gmt":"2026-04-03T18:13:09","guid":{"rendered":"https:\/\/coinsvalue.net\/blog\/285m-bug-or-human-error-solana-based-drift-protocol-suffers-largest-exploit-of-2026\/"},"modified":"2026-04-03T18:13:09","modified_gmt":"2026-04-03T18:13:09","slug":"285m-bug-or-human-error-solana-based-drift-protocol-suffers-largest-exploit-of-2026","status":"publish","type":"post","link":"https:\/\/coinsvalue.net\/blog\/285m-bug-or-human-error-solana-based-drift-protocol-suffers-largest-exploit-of-2026\/","title":{"rendered":"$285M Bug Or Human Error? Solana-Based Drift Protocol Suffers Largest Exploit Of 2026"},"content":{"rendered":"<p style=\"font-weight: 400\">Solana-based Drift Protocol has suffered the largest exploit of 2026 to date, losing nearly $300 million in a \u201chighly sophisticated operation\u201d that has raised concerns about the growing threat of human-targeted attacks in the crypto space.<\/p>\n<h2 style=\"font-weight: 400\">Solana DEX Loses $285M On April Fool\u2019s Day<\/h2>\n<p style=\"font-weight: 400\">On Wednesday, Solana-based decentralized exchange (DEX) Drift Protocol was the victim of an exploit that stole hundreds of millions of dollars from its vaults. After online reports flagged unusual on-chain activity yesterday afternoon, Drift\u2019s official channels confirmed the attack, quickly suspending deposits and withdrawals.<\/p>\n<p><img decoding=\"async\" data-recalc-dims=\"1\" loading=\"lazy\" class=\"size-large wp-image-890294\" src=\"https:\/\/www.newsbtc.com\/wp-content\/uploads\/2026\/04\/Captura-de-pantalla-2026-04-02-a-las-11.55.34-a.-m.png?w=860&#038;resize=860%2C271\" alt=\"solana\" width=\"860\" height=\"271\" \/><\/p>\n<p style=\"font-weight: 400\">According to reports, the attack lasted less than 20 minutes and stole around $285 million in multiple assets, including USDC, JPL, USDT, JUP, USDS, WBTC, and WETH, from nearly 20 vaults. This marks the largest crypto exploit of 2026 to date, and one of the largest hacks in the industry, just above WazirX\u2019s $235 million hack.<\/p>\n<p style=\"font-weight: 400\">The hack wiped out half of the Solana-based project\u2019s total value locked (TVL), which fell from roughly $550 million to $252 million, per DeFiLlama data. Drift protocol\u2019s token, DRIFT, also plunged, retracing nearly 40% over the past 24 hours.<\/p>\n<p style=\"font-weight: 400\">Within hours, the exploiter had swapped $270.9 million into USDC, bridged them from Solana to Ethereum via the CCTP TokenMessengerMinterV2, and purchased 129,000 ETH, splitting them across multiple wallets.<\/p>\n<p style=\"font-weight: 400\">In a Thursday post, Drift <a href=\"https:\/\/x.com\/DriftProtocol\/status\/2039564437795836039?s=20\" target=\"_blank\" rel=\"noopener nofollow\">shared<\/a> the details of the incident, affirming that \u201ca malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift\u2019s Security Council administrative powers.\u201d<\/p>\n<p style=\"font-weight: 400\">Solana\u2019s durable nonces are an advanced mechanism that allows transactions to bypass the typical short expiration date of regular transactions. This enables users to pre-sign transactions for future execution, offline signing, or complex multisig workflows.<\/p>\n<p style=\"font-weight: 400\">\u201cThis was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution,\u201d the post continued.<\/p>\n<h2 style=\"font-weight: 400\">Malicious Actors Targeting Humans, Not Smart Contracts<\/h2>\n<p style=\"font-weight: 400\">The Solana-based DEX emphasized that the exploit was not the result of a bug in Drift\u2019s programs or smart contracts, noting that they found no evidence of compromised see phrases either.<\/p>\n<p style=\"font-weight: 400\">\u201cThe attack involved unauthorized or misrepresented transaction approvals obtained prior to execution, likely facilitated through durable nonce mechanisms and sophisticated social engineering,\u201d the project underscored.<\/p>\n<p style=\"font-weight: 400\">Lily Liu, President of the Solana Foundation, <a href=\"https:\/\/x.com\/calilyliu\/status\/2039652201342050713?s=20\" target=\"_blank\" rel=\"noopener nofollow\">addressed<\/a> the incident, asserting that it is a blow to the whole Solana ecosystem. Liu pointed out that \u201cSmart contracts held up. The real targets now are humans: social engineering and opsec weaknesses more than code exploits.\u201d<\/p>\n<p style=\"font-weight: 400\">Ledger CTO Charles Guillemet <a href=\"https:\/\/x.com\/P3b7_\/status\/2039607161328742746?s=20\" target=\"_blank\" rel=\"noopener nofollow\">linked<\/a> Drift\u2019s attack method to Bybit\u2019s $1.4 billion hack, which was attributed to North Korean hacking groups. As he explained, the attackers likely compromised several machines belonging to multisig signers through long-term infiltration and misled operators into approving the malicious transactions.<\/p>\n<blockquote>\n<p style=\"font-weight: 400\">This modus operandi is similar to the Bybit hack last year, widely attributed to DPRK-linked actors. The pattern is becoming familiar: patient, sophisticated supply-chain-level compromise targeting the human and operational layer, not the smart contracts themselves.<\/p>\n<\/blockquote>\n<p style=\"font-weight: 400\">Guillemet affirmed that the incident is \u201cyet another wake-up call for the industry\u201d to raise the bar on security. \u201cUltimately, security is not just about code audits. It&#8217;s about giving operators and users the right information at the right time, so they can make informed decisions about what they sign,\u201d he concluded.<\/p>\n<p><img decoding=\"async\" data-recalc-dims=\"1\" loading=\"lazy\" class=\"size-large wp-image-890293\" src=\"https:\/\/www.newsbtc.com\/wp-content\/uploads\/2026\/04\/SOLUSDT_2026-04-02_09-43-23.png?w=860&#038;resize=860%2C527\" alt=\"Solana, sol, solusdt\" width=\"860\" height=\"527\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solana-based Drift Protocol has suffered the largest exploit of 2026 to date, losing nearly $300 million in a \u201chighly sophisticated operation\u201d that has raised concerns about the growing threat of human-targeted attacks in the crypto space. Solana DEX Loses $285M On April Fool\u2019s Day On Wednesday, Solana-based decentralized exchange (DEX) Drift Protocol was the victim&hellip;<\/p>\n","protected":false},"author":1,"featured_media":10983,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[1846,2844,1863,33,5116,5117,5118,5119,200,82,1222,5120,214,1585],"class_list":["post-10982","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency-market-news","tag-bybit-hack","tag-crypto-exploit","tag-crypto-hack","tag-cryptocurrency-market-news","tag-drift-protocol","tag-drift-protocol-exploit","tag-ledger-cto","tag-lily-liu","tag-sol","tag-solana","tag-solana-ecosystem","tag-solana-foundation","tag-solusdt","tag-usdc"],"_links":{"self":[{"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/posts\/10982","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/comments?post=10982"}],"version-history":[{"count":0,"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/posts\/10982\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/media\/10983"}],"wp:attachment":[{"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/media?parent=10982"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/categories?post=10982"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinsvalue.net\/blog\/wp-json\/wp\/v2\/tags?post=10982"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}