“Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers,” the Drift team wrote.
The project’s X account added:
“This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.”
“We are ready to speak.”
The Drift incident produced one clear lesson that most of the industry already knew but had not fully applied: a timelock is not optional. The removal of that single safeguard on March 27 converted a complex, multi-week attack into a 12-minute cash-out. Protocol governance without a delay mechanism is governance with an open door.
FAQ What happened to Drift Protocol? Attackers drained $286 million from Drift Protocol on April 1, 2026, using fake collateral and pre-signed administrative transactions to empty the protocol’s core vaults in 12 minutes. Who is responsible for the Drift Protocol hack? Security firms, including Elliptic and TRM Labs, have attributed the attack to DPRK-linked threat actors, citing laundering patterns and onchain timestamps consistent with Lazarus Group tradecraft. Is my money safe on Drift Protocol? Drift suspended all deposits and withdrawals following the attack; users in affected protocols like Pyra and Carrot remain unable to access funds as of April 3, 2026. What is a durable nonce attack in Solana DeFi? A durable nonce attack uses a legitimate Solana feature to pre-sign transactions that look routine, holding them as live authorization keys until the attacker chooses to execute them.


















