Blog

Drift's $285 Million Heist Started With a Person, Not a Bug

Written by tortue974 - August 26, 2026

Drift Protocol's $285 million loss on April 1 was not a smart contract bug in the traditional sense. Security firm TRM Labs traced the attack to UNC4736, a North Korean state-sponsored hacking group that spent roughly six months running a social engineering campaign against Drift team members.

The attackers gained access to a privileged admin key. Once inside, they whitelisted a worthless token called CVT as collateral, artificially priced it through manipulated oracles, deposited 500 million CVT, and withdrew $285 million in USDC, SOL and ETH. The entire drain took about 12 minutes.

The market felt it immediately. Drift's total value locked collapsed from $550 million to under $300 million within an hour. The stolen funds were partially bridged to Ethereum through Circle's Cross-Chain Transfer Protocol, then converted into ETH and routed through centralized exchanges. Chainalysis has published a detailed post-mortem breaking down the laundering trail.

The lesson here is uncomfortable for DeFi builders, because Drift's smart contracts had been audited multiple times by reputable security firms. The code was not the entry point, and the vulnerability had nothing to do with Solana's architecture. The humans who held the admin keys were the weakest link, and a determined state-sponsored group found them.

Six months of patience, one admin key, twelve minutes. The audits were fine; the perimeter was made of people. The same is true of almost every service you use, which is why Vulpine strips out the classic levers - no email, no phone number, no reset flow to social-engineer, just a token shown once and messages that remain worthless ciphertext to whoever ends up holding the server.

← All articles
Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.