Skip to content
PROTOCOL RESEARCH

Drift risk

Largest Solana perp DEX, but drained of ~$285M (over half its TVL) in an April 1 2026 governance-takeover hack; users not yet made whole and the protocol is mid-reboot, so it is uninvestable today.
AvoidResearched Jul 1, 2026
strong: Audits & contractsTrail of Bits (2022-23, no highs), Neodyme (protocol-v2, 2024), OtterSec (Connect Snap) all confirmed on docs.drift.trade; code held and was bypassed via admin, not broken.
weak: Admin controlSquads V4 Security Council was 2-of-5 with zero timelock (migrated ~5 days pre-hack); two tricked signatures plus durable nonces gave attackers full protocol control.
watch: OraclePyth with validity spectrum, TWAP sanitization and ~10% price-band guard rails, but the hack whitelisted a fake token (CVT, no Pyth feed) on an attacker-set oracle via admin rights.
weak: Liquidity & exitOver 50% of assets drained; users hold transferable IOU recovery tokens against a revenue-funded pool, not guaranteed dated reimbursement.
watch: Yield (real vs emission)Perp/borrow fees and Insurance Fund yield are real, but the exchange is mid-reboot so current yield is not a reliable live figure.
watch: Holder concentrationDRIFT governance token plus a new IOU recovery token; distribution not verified this run (refresh).
weak: Track recordOne catastrophic incident: April 1 2026, ~$285M drained, second-largest exploit in Solana history (behind Wormhole $326M), still unresolved.
🟢 strong🟡 watch / caveat🔴 weak / fund-loss risk
Verdict is a gate (worst flaw wins), not an average. Our read, not financial advice.
auto-sourced now
TVL$217.5M
30d↑5%
Audits0
Last hack$285.0M · Apr 2026

DeFiLlama + our exploits feed. Cross-check the dated report against today.

TL;DR

Drift is the largest Solana perp DEX, and on April 1, 2026 it was drained of about $285M, over half its TVL, in a governance takeover. Attackers spent months social-engineering the team, then used Solana durable nonces to get two of five Security Council multisig signers to pre-sign transactions that handed over admin control. With admin rights they whitelisted a fake token (CVT) they had built a fake oracle price for, deposited 500M of it, and withdrew real assets (largest lines were JLP, USDC, cbBTC, WETH). Mandiant attributed it to the DPRK group UNC6862. The smart-contract code was audited and clean; the breach was the humans and the admin pipeline around it. As of this report the protocol is mid-reboot, migrating to USDT, and affected users hold IOU "recovery tokens" against a revenue-funded pool, not their money back. This is a fund-loss event on the primary surface within the last quarter.

Checklist

Audits and contracts. Real and Tier-1: Trail of Bits (2022-23, no highs), Neodyme (2024, protocol-v2), OtterSec (Connect snap). The code held. It was bypassed by admin abuse, not broken. Admin control. The failure point. Squads V4 Security Council was 2-of-5 with zero timelock, migrated only about five days before the hack; two tricked signatures plus durable nonces equalled full protocol control. A reboot with new controls is underway but unproven. Oracle. Normally Pyth with TWAP and validity guard rails. In the hack the attacker whitelisted a token (CVT) that has no Pyth feed and set a custom oracle address they controlled, so the oracle defense was routed around via admin, not defeated head-on. Liquidity and exit. Broken right now. Over 50% of assets were drained; users hold transferable recovery-claim tokens against a $147.5M Tether-backed pool that fills from future revenue. No guaranteed, dated repayment. Yield: real vs emission. Perp/borrow fees and Insurance Fund staking yield are real when the exchange runs, but the exchange is in relaunch, so current yield is not a live, reliable figure. Holder concentration. DRIFT governance token plus a new IOU recovery token; distribution not verified this run. refresh Track record. One catastrophic incident, April 1 2026, ~$285M, second-largest exploit in Solana history. Recent, unresolved, and central.

Worst case

Already happened. Admin control was seized and roughly $285M left the vaults in about twelve minutes. The forward worst case is that the USDT reboot underperforms, the revenue-funded recovery pool never fully covers the IOU tokens (total user losses are put near $295M against a pool that started near $3.8M and is capped around $147.5M of committed support), and holders of recovery claims are left with a discounted or worthless asset. A secondary worst case is a repeat: reboots are the least-audited version of any protocol, and the attacker class (state-sponsored social engineering) targets people and process, which a code re-audit does not fully fix.

Bottom line

Avoid. This is not a close call and not an averaging exercise. A perp DEX that lost over half its TVL to a governance takeover about 90 days ago, that has not made users whole, and that is still rebuilding is uninvestable for the $10k showcase today. The right posture is to wait: let the reboot ship, let the new admin model (higher threshold, timelock, signer hygiene against durable-nonce abuse, key rotation) be published and audited, let the recovery pool demonstrate it actually pays down the IOUs, and let a few clean months of operation accrue. Re-rate then, not before.

Data appendix

  • TVL: ~$217M (DeFiLlama "drift", 2026-07-01, verified). Down from a pre-hack level reported around $550M; ~$285M (>50% of TVL) was drained on April 1, 2026. For a perp DEX, open interest matters more than TVL; the AMM plus a per-asset Insurance Fund is the counterparty and backstop, with explicit socialized-loss if the Insurance Fund is depleted (Drift docs). Live OI / perp volume breakdown: refresh (DeFiLlama DEX-summary endpoint errored this run).
  • Audits: Trail of Bits (Nov 2022-Jan 2023, no high-severity findings, fix review completed), Neodyme (protocol-v2, Feb-Apr 2024, low finding volume), OtterSec (Connect-by-Drift snap). Source: docs.drift.trade/security/audits and drift.trade/audit. Note: none of these prevented the April 2026 breach because it was an operational/admin compromise, not a contract bug.
  • Admin/governance: Drift on Solana using the Squads V4 multisig framework. At the time of the hack the Security Council was 2-of-5 with zero timelock, migrated only about five days prior (BlockSec, Chainalysis, QuillAudits). The upgradeable program was controlled by that multisig, which is exactly how admin control was transferred to the attacker. Post-hack reboot led by a new Head of Protocol (Noah Prince, ex-Helium) with the Gauntlet team; planned changes include a new community-governed multisig, time-locked operations, dedicated signing devices, independent transaction verification, key rotation, and reduced product scope (perps-focused). New threshold/timelock config not yet published. refresh once relaunch admin model is public.
  • Oracle: Pyth, with an on-chain validity spectrum (Invalid/TooVolatile/TooUncertain/Stale/Valid), TWAP sanitization gated by ContractTier (within 10/20/50% of last TWAP), and roughly 10% oracle-vs-AMM price-band circuit breakers (Drift protocol-guard-rails docs). In the exploit the attacker configured a custom oracle they controlled for the fake CVT collateral (CVT has no Pyth feed), whitelisted via stolen admin rights.
  • Insurance Fund / backstop: Per-asset Insurance Funds; stakers earn fees and absorb bankruptcies; excess losses socialized across traders/lenders (Drift docs). Did not cover a ~$285M admin-level theft, which is outside its design scope.
  • Recovery status (2026-07-01): Full protocol reboot in progress, migrating settlement to USDT; up to ~$147.5M recovery support ($127.5M Tether + $20M partners); users receive transferable recovery-claim tokens (IOUs) funded by future revenue, not immediate reimbursement (Drift updates Apr 16 / May 5 / Jun 3 2026; CoinDesk; The Block; KuCoin). Total user losses put near $295M. Mandiant conclusively attributed the attack to DPRK group UNC6862.
  • Holder concentration: refresh (DRIFT token address solana:DriFtupJYLTosbwoN8koMbEYSx54aFAVLddWsbksjwg7 per DeFiLlama; distribution not pulled this run, and a new IOU token now exists alongside it).
  • Recent-news scan: Dominated by the April 1 2026 hack and the ongoing recovery/reboot. No evidence of a second incident this run. Maintained monthly. Methodology: DeFi Research Instruction v2.

← all protocols