On April 1, 2026, Solana's largest decentralized perpetual futures exchange Drift Protocol suffered an attack, losing approximately $285 million. This is the second-largest DeFi hack of 2026 (behind KelpDAO's $292M attack the same month). Together, these two incidents totaled $577M — 76% of all DeFi stolen funds in 2026.

Key Finding: This was not a smart contract vulnerability. The attacker penetrated protocol personnel through social engineering, used Solana's durable nonce feature to pre-sign malicious transactions, and drained the entire treasury in 12 minutes. Mandiant confirmed the attacker as North Korean state-sponsored APT group UNC6862.

⏱️ Attack Timeline

Time

Event