/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Solana-based DeFi platform Drift warns users about an “active attack” on its protocol; Arkham data: $250M+ moved from Drift to a wallet, which now holds <$600K

CoinDesk Helene Braun

Context & Ripple Effects

The incident followed two consecutive alerts in which on-chain tracking showed more than $250M moving from Drift-controlled addresses into an interim wallet. The wallet’s rapidly diminished balance made the immediate issue not just detecting a compromise, but tracing assets once they had moved onward.

Later reporting attributed the broader theft to a prolonged social-engineering operation, with Drift describing a suspected six-month infiltration by attackers posing as a trading firm. The episode became part of a wider DeFi confidence shock: subsequent coverage linked major protocol hacks, including Drift, to substantial investor withdrawals from the sector.

First-order effects

  • Drift users and counterparties face an immediate security and liquidity-risk event while the protocol investigates the attack and tracks funds that have already left the visible interim wallet.
  • Arkham’s on-chain observations give investigators and users a public trail, but the low remaining wallet balance suggests the suspected attacker had already dispersed much of the moved value.

Second-order effects

Third-order effects

  • If repeated social-engineering-led breaches continue, DeFi risk assessment will shift further from smart-contract audits alone toward operational security, counterparty verification, and incident-response readiness.
  • Public blockchain data can improve post-incident tracing, but it does not prevent rapid asset dispersion; the durable competitive divide may be between protocols that can demonstrate both transparent monitoring and credible safeguards around human access points.

The trend: This is one data point in DeFi’s shift from code-only security assumptions toward broader operational-risk controls as protocols seek to retain user trust after large exploits.

Discussion

  • @driftprotocol @driftprotocol on x
    We are observing unusual activity on the protocol. We are currently investigating. Please do not deposit funds into the protocol while we investigate. This is not an April Fools joke. Proceed with caution until further notice. We'll provide additional updates from this account.
  • @driftprotocol @driftprotocol on x
    Drift Protocol is experiencing an active attack. Deposits and withdrawals have been suspended. We are coordinating with multiple security firms, bridges, and exchanges to contain the incident. This is not an April Fools joke. We'll provide additional updates from this account as
  • @lookonchain @lookonchain on x
    The Drift Protocol exploiter is swapping the $270M+ stolen assets into $USDC, then bridging to #Ethereum to buy $ETH. 🚨 So far, they have bought 19,913 $ETH ($42.6M). https://intel.arkm.com/... https://x.com/... [image]
  • @fabianosolana @fabianosolana on x
    Drift had a 2/5 multisig with 0 timelock $280M gone... I checked other defi protocols on Solana: - Jupiter Lend: 4/7 (with 12h timelock) - Kamino: 5/10 (with 12h timelock) - Loopscale: 3/5 - Solstice: 3/5 (with 1d timelock) - Exponent: 2/3 [image]
  • @lookonchain @lookonchain on x
    Drift Protocol appears to have been exploited, with over $270M in assets suspiciously transferred to wallet HkGz4K. 🚨 That's crazy! https://intel.arkm.com/... [image]
  • @newmichwill Michael Egorov on x
    Almost wanted to say something about code safety, but hearing it's not even that. Sounds like a usual risk management failure in a lending protocol + drain via a “weak collateral”. Anyhow, DeFi on Ethereum went over these lessons already. Solana ecosystem is still learning
  • @loopify @loopify on x
    bro said unusual activity it's $270M that got drained
  • @godenis Denis Dariotis on x
    Drift hack + Backpack TGE issues show why Solana DEX volume is struggling. Public order books = easy front-running. Hyperliquid is winning. @GoDark fixes it: decentralized dark pool on Solana. Hidden orders. No MEV. Full self-custody. Fast and private execution.
  • @stevensarmi Steven on x
    Watch who starts bashing in times like these when people are down, get receipts because those people you should unfollow/block. This is a terrible look on our entire industry. This is a very shit situation, we don't know how the exploit/hack happened, what the vector was,
  • @perena @perena on x
    A quick note on the recent developments around Drift. USD* is not affected. USD* has no counterparty exposure to Drift, and USD*'s yield strategies do not depend on Drift. However redemptions are temporarily paused as a precaution to ensure user safety.
  • @phantom @phantom on x
    We're aware of reports regarding Drift Protocol, and our security team is investigating. Users trying to access Drift through Phantom will see a required warning that there may be unique risks in accessing Drift right now. Those who still want to access their funds will have the
  • @jupiterexchange Jupiter on x
    Jupiter is not affected by the Drift situation. Jupiter Lend has no exposure to Drift's markets and JLP is fully backed by the underlying assets. That said, this a difficult day for Solana DeFi and our heart goes out to the Drift team and everyone affected.
  • @wazzcrypto @wazzcrypto on x
    Drift summary: - $200M stolen and no one noticed for an hour - Apparently a single compromised admin key (lol) - Hacker still came in for seconds 2 hours after the hack to drain a few extra millions - Hacker still bridging out $USDC 3 hours after the hack wp everyone
  • @lookonchain @lookonchain on x
    The Drift Protocol exploiter also deposited $SOL into #HyperLiquid and sold it to buy $ETH. The Drift Protocol exploiter even deposited $SOL into #Binance. https://intel.arkm.com/... https://x.com/... [image]
  • @azflin @azflin on x
    “Solana DeFi never gets hacked bro” “Contracts are unverified so hackers can't read the source code to attack” 🤣🤣