Solana-based Drift Protocol, the largest decentralized perpetual futures exchange on the blockchain, experienced a massive security breach on April 1, 2026, losing $286 million in what appears to be a North Korea-linked attack. The exploit occurred in just 12 minutes after attackers spent three weeks manufacturing fake collateral and socially engineering the protocol's signers. Elliptic identified multiple indicators suggesting DPRK involvement, including on-chain behavior and laundering methodologies consistent with previous North Korean operations. The attack systematically drained three main vaults including JLP Delta Neutral, SOL Super Staking, and BTC Super Staking. Drift's total value locked collapsed from $550 million to under $250 million, making this the largest DeFi hack of 2026 and the second-largest in Solana's history after the 2022 Wormhole exploit. This marks the 18th suspected DPRK-linked crypto theft tracked in 2026, with North Korean groups stealing over $300 million this year.
Drift Protocol Suffers $286M Hack Linked to North Korean Actors
E
Elliptic
Friday, April 3, 2026·5 min read·DeFi
#drift-protocol#hack#north-korea#solana#defi-exploit#lazarus-group
