LIVE BULK Mainnet is live · Invite-only trading is open · Audited by Zellic · Trade now →

· Kael · Security  · 9 min read

Drift Protocol Hack: The $285M April 2026 Exploit, and the Velocity DEX Relaunch

On April 1, 2026, Drift Protocol lost $285M in one of the most sophisticated DeFi exploits on record. It has since rebranded to Velocity DEX, backed by a $127.5M Tether credit line, and remains in beta months later. Here is exactly what happened, how it worked, and where things stand now.

On April 1, 2026, Drift Protocol lost $285M in one of the most sophisticated DeFi exploits on record. It has since rebranded to Velocity DEX, backed by a $127.5M Tether credit line, and remains in beta months later. Here is exactly what happened, how it worked, and where things stand now.

TL;DR

On April 1, 2026, Drift Protocol was exploited for $285M via social engineering and Solana durable nonces. Attackers spent months compromising Security Council members, then executed pre-signed admin transactions to list a fake token as collateral and drain the vaults in 12 minutes. Drift rebranded to Velocity DEX on July 1, 2026, backed by a $127.5M Tether credit line and USDT as its core stablecoin, and has been in private beta since — no confirmed public mainnet date as of September 2026. The attack is attributed to North Korean state-linked group UNC4736.

On April 1, 2026, Drift Protocol — then the leading Solana perpetuals exchange with $550M in TVL — lost $285 million in one of the most technically sophisticated DeFi exploits on record. The attack did not exploit a smart contract bug. It exploited people. Drift has since rebranded to Velocity DEX, backed by a $127.5M Tether credit line, and remains in beta as it works toward a full relaunch.

This page documents exactly what happened, how the attack worked at a technical level, where the protocol stands now under its new identity, and what it means for Solana perp traders.


What Was Drift Protocol?

Drift Protocol launched in 2021 as a native Solana perpetuals exchange. By 2025 it had grown to become the dominant Solana perp venue:

  • Architecture: Hybrid vAMM + central limit orderbook (CLOB) + Just-in-Time (JIT) liquidity
  • TVL peak: ~$550M as of early 2026
  • Markets: 40+ perpetual pairs including BTC, ETH, SOL, and meme tokens
  • Ecosystem depth: Native Solana program, deep DeFi composability, accepted JitoSOL/mSOL/major LSTs as collateral
  • User base: One of the largest non-custodial perp user bases on Solana

It was not a minor venue. Drift was the Solana perps benchmark.


The April 1, 2026 Exploit: What Happened

Timeline

TimeEvent
Months priorSocial engineering campaign targeting Drift Security Council begins
April 1, ~08:00 UTCAttackers execute first pre-signed admin transactions
April 1, ~08:12 UTCVaults drained — approximately $285M removed
April 1, ~08:30 UTCDrift team detects exploit, begins protocol freeze
April 1DRIFT token falls 17–36%, TVL collapses from $550M to under $250M
Days afterProtocol froze operations, removed compromised multisig wallets
June 2026Drift TVL: ~$6M. Recovery ongoing.
July 1, 2026Drift rebrands to Velocity DEX, backed by a $127.5M Tether credit line; USDT replaces USDC as core stablecoin
July–August 2026Velocity DEX private beta rolls out; fees and SOL/USDT margin mechanics progress through beta
September 2026No confirmed public mainnet relaunch date yet

The Attack Vector: Social Engineering + Durable Nonces

The Drift hack did not exploit a vulnerability in Drift’s smart contracts. It exploited two things in combination:

1. Solana durable nonces

Standard Solana transactions expire after approximately 150 blocks (~60 seconds). Durable nonces are a Solana feature designed for offline signing — they allow a transaction to be signed and stored indefinitely, with no expiry, and executed at any future time.

This feature has legitimate uses: cold wallet operations, multisig workflows, scheduled transactions. It also creates a specific attack surface: if an attacker can get someone to sign a durable nonce transaction without fully understanding what they signed, that signature remains valid and executable indefinitely.

2. Social engineering of the Security Council

Attackers — widely attributed to North Korean state-linked group UNC4736 (the same group behind the $600M Ronin Bridge hack) — spent months building relationships with and compromising Drift Security Council members. They posed as contributors, researchers, and protocol participants.

Over this period, they induced Security Council members to unknowingly pre-sign administrative transactions using Solana’s durable nonces feature. The transactions were framed as routine governance operations. The actual transaction payloads established the conditions for the exploit.

3. Execution

On April 1, 2026, attackers executed the stored transactions in sequence:

  1. Listed a fake token (“CarbonVote Token”) as valid Drift collateral
  2. Raised withdrawal limits on the protocol
  3. Deposited CarbonVote Token as collateral at inflated valuation
  4. Withdrew real assets against the fake collateral
  5. Complete vault drain in approximately 12 minutes

Drift’s on-chain security worked exactly as designed. The attack bypassed it entirely by operating through legitimate admin authority — authority that had been compromised through human deception, not technical exploitation.


Why This Attack Was Different

Most DeFi hacks exploit a technical flaw: a reentrancy bug, an oracle manipulation, a price calculation error. Those are fixable. You patch the contract.

The Drift hack exploited institutional trust and human cognition under sustained deception. The attacker’s position was indistinguishable from a legitimate contributor for months. The signed transactions appeared legitimate at signing time.

This is the same playbook as the Ronin Bridge attack ($600M, 2022) and the Harmony Horizon Bridge attack ($100M, 2022) — both attributed to North Korean groups using long-term social engineering to compromise signing authority before executing a rapid drain.

The Solana-specific element: Durable nonces made the deception scalable. The attackers did not need to deceive multiple council members simultaneously — they could accumulate signatures over months, at each council member’s convenience, and execute when all pieces were in place.


Impact on the Solana Perps Ecosystem

Drift’s collapse redistributed volume across the Solana ecosystem rather than concentrating it elsewhere. The May 2026 $76.7B monthly perps volume record — a 34% increase over the prior high — arrived in this fragmented, post-Drift landscape. It proves the underlying demand was never dependent on Drift alone.

The current landscape (as of September 2026, mixing last-verified TVL snapshots per platform):

PlatformTVLStatus
Jupiter Perps$636M–$1.38B (June 2026)Live
BULK ExchangeN/A — mainnet trading, not deposit-basedLive since Sept 5, 2026, Zellic-audited
Phoenix Trade~$30M (June 2026)Live
GMTrade~$43–45M (June 2026)Live
Pacifica~$38–42M (June 2026)Live
Drift / Velocity DEX~$6M at trough (June 2026)Rebranded, private beta since July 2026

Full ecosystem breakdown: State of Solana Perps 2026


Drift’s Current Status: Rebranded to Velocity DEX

Drift did not shut down, but it also no longer operates under the Drift name. On July 1, 2026, the protocol rebranded to Velocity DEX, positioning the new name around “a cleaner architecture, a stronger security foundation, and a clearer sense of what this platform is for.” For the full comparison against BULK — including the audit gap Velocity’s own docs admit to — see BULK vs Velocity DEX.

What changed with the rebrand:

  • $127.5M credit line from Tether — conditional on switching the platform’s core margin stablecoin from USDC to USDT
  • Instruction-level audits and time-locked admin actions, reviewed under Solana’s STRIDE security program — a direct structural response to how the original hack exploited unaudited, unrestricted admin authority via durable nonces
  • Private beta since July 2026, with fee and margin mechanics (SOL/USDT collateral, sub-0.02% fees reported in beta) progressing through August 2026
  • No confirmed public mainnet relaunch date as of September 2026 — the platform has been in beta for two-plus months

The technical architecture that made Drift impressive before April 1 — hybrid vAMM + CLOB + JIT, 40+ markets, deep Solana DeFi integration — is being rebuilt under Velocity DEX’s name, with Tether’s backing replacing the trust that was lost. Whether users return depends on how the beta-to-mainnet transition goes and how long the security overhaul takes to prove itself in production.

Honest assessment: A $127.5M backstop from Tether is a real vote of confidence, and instruction-level audits address the actual failure mode (unaudited admin authority), not just a cosmetic rebrand. But “trust rebuild” in DeFi is measured in quarters or years, not weeks — and a protocol still in private beta five months after a nine-figure hack is not yet a like-for-like alternative to an exchange with an established, functioning mainnet.


Key Lessons: What This Attack Teaches

For traders:

  • Custodial risk at the protocol level is distinct from smart contract risk. An admin key compromise can drain funds that survive a contract audit.
  • Fragmented liquidity across multiple venues is more resilient than single-venue dominance.
  • Trading or farming AURA on newer venues carries meaningful smart contract and operational risk — but the alternative (concentration in an established venue whose admin authority just got compromised) has its own risk profile, as Drift demonstrated.

For protocol design:

  • Durable nonces require explicit governance around what operations are permissible as durable transactions, who can sign them, and how signing is verified.
  • Security Council operations should require time-locked execution with a transparent on-chain record, so signed admin transactions are visible before execution.
  • Social engineering resistance requires operational security practices beyond smart contract audits.

For the ecosystem:

  • Solana perps trading volume reached a new ATH despite the loss of the category leader. Ecosystem resilience was demonstrated.
  • No single venue concentration is structurally fragile. The May 2026 record was built on distributed volume.

Looking for a Drift/Velocity Alternative Right Now?

If you traded on Drift before the hack and don’t want to wait out Velocity DEX’s beta-to-mainnet transition, the State of Solana Perps 2026 covers the full current landscape including Jupiter Perps, Phoenix Trade, GMTrade, and BULK Exchange. Each has different tradeoffs in architecture, liquidity, and fee structure.

BULK Exchange is live on mainnet now, not in beta:

  • No prior security incidents, and a completed Zellic audit (confirmed August 17, 2026) ahead of launch
  • 5-of-8 multisig with a 3-hour timelock on upgrade/admin authority — the structural fix Velocity DEX is still building toward
  • 0bps maker fees through the Genesis Phase (~October 5, 2026)
  • 30% community token allocation via AURA — earned by trading, holding BulkSOL, and referrals
  • L0 architecture with portfolio margin and 5–20ms execution
  • BulkSOL yield composable with Exponent, Loopscale, and Titan

You don’t have to pick one exchange forever — but if you’re weighing “wait for Velocity’s mainnet” against “trade somewhere live today,” BULK is the one that’s already running. See Is BULK Safe? for the honest risk picture before you move size.

Trade on BULK Exchange →



Back to cluster hub: Best Solana Perp DEX 2026

Also in this cluster:

Security & architecture:

The broader tokenless DEX landscape (all chains):

Browse the full BULK Exchange glossary

Try BULK Exchange → app.bulk.trade

Last updated: September 7, 2026 — added the Velocity DEX rebrand and Tether-backed relaunch details.

0 bps maker fees end ~October 5, 2026.

BULK's Genesis Phase waives maker fees for the first 30 days of mainnet. Trading is invite-only — a free access code plus a referral link gets you in.

Get Access & Trade →
Back to Blog

Related Posts

View All Posts »
Is BULK Safe? A Risk Guide

Is BULK Safe? A Risk Guide

BULK Exchange mainnet is live and Zellic-audited, but "safe" means different things for a perp DEX than for a bank. Here is every risk category — protocol, custody, market, and phishing — ranked by how much it actually matters.

Is BULK Exchange Legit? On-Chain Verification and Risk Assessment

Is BULK Exchange Legit? On-Chain Verification and Risk Assessment

$39.5M USDC flowed into BULK's Season 1 pre-deposit vault before it closed at mainnet launch on September 5, 2026 — all verifiable on-chain. Mainnet is live and audited by Zellic. Here's what the data shows, what requires trust, and what the real risks actually are.

BULK Mainnet is live

Invite-only trading is open now

Trade →

BULK Mainnet is live

Invite-only trading is open now

Trade →