ChainBleedv0.1 · open intel
← back to feed·SOLSOCIAL-ENGINEERING2026-04-01 · 2mo ago
Incident · CHAINBLEED

Drift Protocol

DPRK-linked Privileged-Access Drain
Estimated loss
$286.00M
VERDICT —OUT OF SCOPE
Out of scope for a source-code audit. The root cause was a six-month DPRK social engineering operation culminating in privileged-access compromise, not a smart-contract vulnerability. Source review fuzzes invariants and models adversaries — but it cannot prevent employees being phished or admin keys being compromised through operational channels. What WOULD apply: operational-security review (key management, multi-sig posture, hot-wallet exposure, role-grant audit), threat-model briefing on DPRK tradecraft, and incident-response readiness — categories adjacent to but distinct from contract audit.
▰ METHOD
Privileged-Access Compromise via Social Engineering
SOCIAL-ENGINEERING
Root cause

Multi-month DPRK-attributed social engineering operation culminating in privileged-access compromise; attacker drained ~$285-286M in user assets in ~12 minutes, then bridged to Ethereum within hours.

Forensic narrative

Drift Protocol — the largest perpetual futures DEX on Solana — was drained of ~$285-286M in user assets in roughly 12 minutes on 2026-04-01. Elliptic, TRM Labs, and Chainalysis independently attributed the attack to DPRK-linked actors based on on-chain behavior, laundering methodology, and network-level indicators. Operational tradecraft: the attackers ran a six-month social engineering campaign that included deploying a fake collateral token ('CarbonVote' / CVT) to use as artificial collateral and ultimately to obtain privileged access. Most stolen funds were bridged to Ethereum within hours. This is the largest DeFi hack of 2026 to date and the second-largest security incident in the Solana ecosystem after the 2022 Wormhole bridge exploit.

Primary source
https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack
Sourced from
chainbleed
Technical record
chain
solana
protocol
Drift Protocol
bug_class
social-engineering
date_occurred
2026-04-01
loss_usd
$286,000,000
classification
Infrastructure / Operational Security
technique
Privileged-Access Compromise via Social Engineering
target_type
DeFi Protocol — Perpetual Futures DEX
source_id
cb:drift-protocol-2026-04-01
Related — same bug class· social-engineering
2026-05-11
1mo ago
SOL
Roaring Kitty X Account → $RKC memecoin pump-dump
X account takeover → coordinated memecoin pump-and-dump on Pump.fun
social-engineering
$2.86M
OUT OF SCOPE
2026-02-23
3mo ago
WLFI
Social Engineering
social-engineering
OUT OF SCOPE
2025-09-01
9mo ago
BSC
OlaXBT
Multisig wallet Social Engineering Exploit
social-engineering
$2.00M
OUT OF SCOPE
2025-07-24
10mo ago
MULTI
WOO X
Social Engineering
social-engineering
$14.00M
OUT OF SCOPE
2025-04-27
1y ago
QuantMaster
Insider Manipulation
social-engineering
$100.0K
OUT OF SCOPE
2025-04-11
1y ago
ETH
Jake Gallen
Social Engineering
social-engineering
$100.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence