MEDIUMVulnerability
Global
Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK
Friday, April 3, 2026 at 08:35 AM UTC·Source: The Hacker News
Updated: Friday, April 3, 2026 at 01:53 PM UTC
Executive Summary
Solana-based decentralized exchange Drift has confirmed that attackers drained about $285 million from the platform during a security incident that took place on April 1, 2026. "Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers," the&
Analysis
Solana-based decentralized exchange Drift has confirmed that attackers drained about $285 million from the platform during a security incident that took place on April 1, 2026. "Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers," the&