Solana-based Drift Protocol has suffered the largest exploit of 2026 to date, losing nearly $300 million in a “highly sophisticated operation” that has raised concerns about the growing threat of human-targeted attacks in the crypto space.
Solana DEX Loses $285M On April Fool’s Day
According to reports, the attack lasted less than 20 minutes and stole around $285 million in multiple assets, including USDC, JPL, USDT, JUP, USDS, WBTC, and WETH, from nearly 20 vaults. This marks the largest crypto exploit of 2026 to date, and one of the largest hacks in the industry, just above WazirX’s $235 million hack.
The hack wiped out half of the Solana-based project’s total value locked (TVL), which fell from roughly $550 million to $252 million, per DeFiLlama data. Drift protocol’s token, DRIFT, also plunged, retracing nearly 40% over the past 24 hours.
Within hours, the exploiter had swapped $270.9 million into USDC, bridged them from Solana to Ethereum via the CCTP TokenMessengerMinterV2, and purchased 129,000 ETH, splitting them across multiple wallets.
“This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution,” the post continued.
Malicious Actors Targeting Humans, Not Smart ContractsThe Solana-based DEX emphasized that the exploit was not the result of a bug in Drift’s programs or smart contracts, noting that they found no evidence of compromised see phrases either.
“The attack involved unauthorized or misrepresented transaction approvals obtained prior to execution, likely facilitated through durable nonce mechanisms and sophisticated social engineering,” the project underscored.
This modus operandi is similar to the Bybit hack last year, widely attributed to DPRK-linked actors. The pattern is becoming familiar: patient, sophisticated supply-chain-level compromise targeting the human and operational layer, not the smart contracts themselves.




















