One of the most serious security incidents in the decentralized financial services space has come to light, as Drift Protocol confirmed the loss of approximately $285 million following a targeted cyberattack on April 1, 2026. The platform, which operates on the Solana, revealed that the attackers managed to gain administrative control through a highly sophisticated methodology that did not rely on classic technical errors.

According to the company, the breach did not result from a vulnerability in smart contracts or a leaked seed phrase, but from the abuse of approval mechanisms and advanced social engineering techniques. This is worrying, as it suggests that even mature infrastructures can collapse when the human factor is involved.
See also: Social Engineering: The most dangerous “human” virus
How the attack unfolded and the role of nonces
The attack appears to have relied on the use of “durable nonce” accounts, a technique that allows transactions to be pre-signed and executed at a later time. The attackers exploited this mechanism to delay critical actions, concealing their true intentions until the moment of the attack.
After securing sufficient multisig approvals, they were able to transfer control of the protocol within minutes. They then proceeded to introduce a malicious asset and remove withdrawal restrictions, allowing funds to rapidly drain from the platform.
Preparations for the attack appear to have begun weeks in advance, suggesting a high level of organization and strategic planning.
The fake token and the collapse of control mechanisms
Of particular interest is the creation of the so-called “CarbonVote Token”, a digital asset with no real value. Despite its low liquidity and manipulation of transactions, Drift’s systems recognized it as a valid high-value security.
This development reveals a critical weakness in the protocol’s valuation mechanisms and oracles. When such systems fail to properly assess the reliability of an asset, the path to massive financial losses.
See also: Social Engineering: The Psychology Behind Attacks

Evidence of state involvement and the role of North Korea
Analysis by Elliptic and TRM Labs suggests the possible involvement of groups linked to North Korea. On-chain data, money laundering patterns, and use of services like Tornado Cash align with known tactics attributed to such threat actors.
If confirmed, the incident is part of a broader campaign of cyberattacks aimed at raising funds for state purposes. Estimates indicate that billions of dollars have been stolen through such attacks in recent years, making this activity one of the most organized in the cybercrime arena.
Social engineering as a key attack weapon
One of the most worrying aspects of the case is the increasing use of social engineering. Campaigns like DangerousPassword and Contagious Interview have already proven their effectiveness, targeting developers, administrators, and executives in the Web3 space.
The use of artificial intelligence to create more convincing attacks further increases the risk. Attackers can now construct realistic scenarios, impersonate trusted individuals, and gain access to critical infrastructure without having to exploit purely technical weaknesses.
See also: Salesloft Drift attack linked to GitHub breach
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Broader implications for the crypto ecosystem
The Drift Protocol incident highlights a significant shift in the way attacks are carried out in the cryptocurrency space. The focus is shifting from code bugs to processes, approvals, and the human factor.
For the ecosystem, this means that security can no longer be limited to smart contract. A holistic approach that includes stricter governance mechanisms, better multisig approval control, and ongoing user education.
As attacks become more sophisticated and well-funded, the resilience of platforms will depend on their ability to adapt quickly and anticipate not only technical but also human risks.
