The attackers spent months laying the groundwork for a precision strike against Drift's governance and social trust layers.
1. Fake token creation. The attacker created a worthless token called CarbonVote Token (CVT) with an initial supply of 750 million tokens .
2. Price manipulation. They seeded a tiny $500 Raydium liquidity pool and wash-traded CVT until Drift's oracles recognized it as valid collateral with a perceived price of roughly $1 .
3. Long-term social engineering campaign. Over several months, the attackers posed as representatives of a legitimate quantitative trading firm, cultivating trust with Drift's multisig signers through conference meetings and sustained interaction .
4. Pre-signed transaction trick. The attackers induced multisig signers to pre-approve transactions that appeared routine but actually authorized an administrative takeover of Drift's Security Council .
5. Durable nonce exploit. A "novel attack involving durable nonces" allowed the attacker to assume full admin control with no timelock, exploiting a feature in Solana's architecture .
6. The drain. Once in control, the attacker listed the inflated CVT as valid collateral, removed withdrawal safeguards, and executed 31 rapid withdrawals, draining real user assets — ETH, USDC, SOL, and wrapped BTC — worth roughly $285 million in under 12 minutes .
TRM Labs described the root cause as "a combination of social engineering multisig signers into pre-signing hidden authorizations and a zero-timelock Security Council migration that eliminated the protocol's last line of defense" . The Drift team confirmed the exploit was not a code bug but an operational security failure
.
Immediate halt. Drift paused deposits and trading within an hour of detecting the breach, and issued a public warning that it was "not an April Fools joke" .
Investigation. The team engaged law enforcement and third-party forensics firms — TRM Labs, Chainalysis, Elliptic, and Halborn — to trace funds and identify the attackers . On-chain messages were sent to four Ethereum wallets holding roughly 129,000 ETH of stolen assets
.
Recovery fund. Stablecoin issuer Tether committed to leading a $150M recovery program, with $127.5 million contributed directly by Tether and additional undisclosed partners, to restore user funds and relaunch the platform .
Recovery token model. Affected users received recovery tokens valued at roughly $1 per token representing their verified losses. These tokens function as pro-rata claims on a recovery pool that started with about $3.8 million in remaining protocol assets and the Tether-led $147.5 million pledge .
Security overhaul. Drift implemented strict signer verification, role-based access controls, out-of-band transaction verification, behavioral monitoring of signers, and elimination of pre-signed transaction risks .
In June 2026, Drift announced a comprehensive rebrand. Contrary to some early speculation, the rebrand is not to a name like "Velocity DEX." Instead, Drift is relaunching as a dedicated Solana-based perpetual futures exchange (described as a "Solana Perp DEX") focused exclusively on USDT-based perpetual swap trading .
Key elements of the rebrand:
The Drift hack was the largest DeFi exploit of 2026 and the second-largest in Solana's history . It exposed critical vulnerabilities in governance security and the human layer of multisig operations — vulnerabilities that no amount of smart contract auditing could have prevented.
Drift's response and rebrand represent a pivot from a general-purpose DeFi hub to a single-purpose, high-security perp DEX — an implicit acknowledgment that the previous multi-product surface area created too much governance and operational risk. The narrowed scope, combined with the Tether-anchored recovery fund, new security architecture, and experienced security leadership, is designed to rebuild user trust and recapture Drift's position as Solana's dominant perpetuals exchange.
For the broader Solana ecosystem, the incident has become a reference point for the importance of robust signer verification, behavioral monitoring, and eliminating pre-signed transaction risks in governance systems .