MEDIUMVulnerability
Global

Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK

Friday, April 3, 2026 at 08:35 AM UTC·Source: The Hacker News

Updated: Friday, April 3, 2026 at 01:53 PM UTC

Executive Summary

Solana-based decentralized exchange Drift has confirmed that attackers drained about $285 million from the platform during a security incident that took place on April 1, 2026. "Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers," the&

Analysis

Solana-based decentralized exchange Drift has confirmed that attackers drained about $285 million from the platform during a security incident that took place on April 1, 2026. "Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers," the&
Source Attribution

Originally published by The Hacker News on Apr 3, 2026.

Related Threats