Drift Protocol Experiences $285M Exploit, Suspend Deposits and Withdrawals

Generated by AI AgentAinvest Coin BuzzReviewed byAInvest News Editorial Team
Thursday, Apr 2, 2026 5:13 am ET1min read
CRCL--
SOL--
WBTC--
JUP--
ETH--
USDT--
Aime RobotAime Summary

- Drift Protocol, a Solana-based DEX, suffered a $285M exploit via fake tokens and a compromised admin key.

- Attackers drained assets through oracleORCL-- manipulation, transferring most to EthereumENS-- via cross-chain bridges.

- The breach caused TVL to drop to $250M, with DRIFT token plummeting over 25% and deposits/withdrawals paused.

- Experts highlight DeFi vulnerabilities in smart contracts and oracle security, urging caution for users.

- Circle faced criticism for not freezing stolen USDCUSDC--, as attackers used CCTP to evade detection.

Drift Protocol has temporarily suspended deposits and withdrawals as it investigates the exploit and collaborates with security firms to trace the funds. Blockchain sleuths identified a large outflow of assets, with over $285 million transferred to multiple wallets and laundered through exchanges like JupiterJUP--. This exploit marks one of the largest in SolanaSOL-- history, second only to the 2022 Wormhole breach.

The Drift Protocol's Total Value Locked (TVL) dropped from $550 million to less than $250 million following the breach. Major vaults such as JLP Delta Neutral, SOL Super Staking, and BTC Super Staking were targeted. Users are advised to avoid depositing funds and to revoke wallet approvals until further notice.

The DRIFT token experienced a significant price drop, falling over 25% to below $0.064, raising concerns about investor confidence in the platform. According to blockchain security firm Immunefi, 83% of tokens from hacked platforms fail to recover pre-hack prices. This event has highlighted the vulnerabilities in smart contract security, private key management, and oracle manipulation within the DeFi ecosystem.

DeFi Development Corp. (DFDV), a public company focused on Solana, confirmed it has no exposure to the exploit and reiterated its disciplined treasury strategy. The company's risk management approach and operational resilience remain unaffected by the Drift Protocol incident.

Onchain investigator ZachXBT criticized Circle for not freezing stolen USDC during the exploit. The attacker moved assets through Circle's Cross-Chain Transfer Protocol (CCTP) to EthereumETH--, avoiding TetherUSDT-- (USDT), suggesting anticipation of no intervention.

Drift Protocol remains under active investigation, with no confirmed exploit vector yet identified. Blockchain tools are tracking the suspicious wallet for further activity, and the team is working to restore platform security and transparency.

Investors and users are advised to monitor official channels for updates on the status of the investigation and any potential mitigation measures.

Blending traditional trading wisdom with cutting-edge cryptocurrency insights.

Latest Articles

Stay ahead of the market.

Get curated U.S. market news, insights and key dates delivered to your inbox.

Comments



Add a public comment...
No comments

No comments yet