The 12-Minute Drain: Halborn and the $285M Drift Hack
On April Fools' Day 2026, attackers drained $285 million from Solana's Drift in about 12 minutes without a single contract bug. Halborn's autopsy shows why the audit was never the weak point.
The transaction that handed control of a $285 million protocol to its attacker took one second to execute. At 16:05:18 UTC on 1 April 2026, April Fools’ Day, a proposal landed inside the multisig that governs Drift, one of Solana’s largest perpetual-futures venues. One second later, a second transaction approved it. The admin key of the exchange now belonged to someone who had spent months making sure the people who held that key trusted him.
What followed was not a hack in the sense most readers picture. There was no buffer overflow, no reentrancy loop, no integer that quietly wrapped around to zero. Over roughly the next twelve minutes, the attacker listed a worthless token as collateral, valued it at hundreds of millions of dollars using numbers he had painted onto a price feed himself, and pulled real assets out in thirty-one withdrawals. By the time Drift’s contributors understood what was happening, the money was already bridging to Ethereum. Blockchain-security firm Halborn, which would publish one of the first detailed autopsies, had a familiar conclusion waiting: the contracts did exactly what they were written to do.
Drift is the clearest case yet of a shift that has defined crypto security in 2026. The attack surface has moved off the code and onto the humans, the keys, and the control plane that sits above both. This is the story of how $285 million left a protocol that passed its audits, told through the firm whose business is now less about reading Solidity and Rust than about reconstructing the hour everything went wrong.
An April Fools’ Day Drain
Drift Protocol is a decentralized exchange for perpetual futures built on Solana, the kind of venue where traders take leveraged long and short positions and post collateral to back them. On 1 April it held hundreds of millions of dollars in user deposits. By the end of the day it had lost an estimated $285 million, more than half of its total value locked, according to Chainalysis, which reconstructed the drain transaction by transaction.
The number alone put Drift in rare company. It was, at the moment it happened, the largest crypto exploit of 2026 and the second-largest in Solana’s history, behind only the $326 million Wormhole bridge hack of February 2022. It would be overtaken seventeen days later, when the Kelp DAO restaking protocol lost $292 million to the same adversary, and twice more in September. But in the first week of April, Drift was the benchmark for how bad a year this was going to be.
The detail that made security researchers stop was not the size. It was that the exploit never touched a vulnerability in Drift’s smart contracts. TRM Labs, Chainalysis and Halborn all converged on the same reading: the attacker did not break the protocol’s code, he borrowed the protocol’s own authority. He got the people with the keys to sign his transactions for him, weeks in advance, and he did it so quietly that the signatures looked like routine governance housekeeping right up until they emptied the treasury.
What Drift Was, and Why It Was Worth the Effort
To understand why Drift justified a six-month investment, it helps to know what it does. A perpetual-futures DEX lets users bet on the price of an asset with leverage and no expiry date, funded by a collateral balance that the protocol constantly marks against live prices. If you want the mechanics of how those positions open, fund and close, HOGE Wire’s field guide to on-chain futures walks through the plumbing, and a companion piece explains what actually happens when you get liquidated.
The point for an attacker is that a perps venue is a deep, liquid pool of other people’s collateral, and that collateral is a basket of valuable tokens. When Drift was finally drained, the loot was not one asset but at least eighteen, Chainalysis found, including roughly $159.3 million in Jupiter’s JLP liquidity token, $71.4 million in USDC, and $11.3 million in Coinbase’s wrapped bitcoin, cbBTC. Drift sat near the center of a web of Solana DeFi, so the shock radiated outward: at least twenty protocols saw disruptions, pauses or losses through the composability links that make Solana efficient and fragile in equal measure.
The other thing that made Drift attractive was how it was governed. Like most serious protocols, it did not leave its admin powers in a single hot wallet. It used a Security Council, a small group of trusted signers who collectively held the keys to privileged actions: listing new collateral, changing risk parameters, adjusting withdrawal limits. That design is supposed to be a strength. In Drift’s case it became the surface the attacker spent half a year learning how to turn.
The Long Con: Months Across a Table
The operation did not begin in April. According to Chainalysis, the relationship-building started as early as the autumn of 2025. The attackers presented themselves as a quantitative trading firm, the sort of counterparty a growing perps protocol is glad to meet. They approached Drift contributors at crypto conferences, kept the conversation going on Telegram, joined working sessions, and, to prove they were real, deposited more than a million dollars of genuine capital onto the platform. For months they behaved exactly like a legitimate partner, because for the purposes of the con, they were one.
That patience is what separates the Drift hack from the remote, phishing-email intrusions that defined earlier years. Ari Redbord, Global Head of Policy and Government Affairs at TRM Labs, described the campaign to CoinDesk as something new: “North Korean proxies sitting across a table from protocol employees over a period of months. That is, to my knowledge, unprecedented in North Korea’s crypto hacking campaign.” He added the line that has stuck to the whole episode: “This is no longer just a remote keyboard operation.”
The point of all that face time was not to steal a password. It was to earn enough trust that when the attackers eventually asked the Security Council to sign something, the signers would do it without inspecting every byte. Social engineering at this depth does not defeat a security control; it recruits the humans operating it. The same playbook, scaled by automation, is what makes software agents holding private keys such a nervous subject right now, a worry HOGE Wire examined in asking whether you can trust an Eliza agent with a wallet.
Durable Nonces: Signatures That Never Expire
The technical pivot of the Drift hack is a Solana feature called a durable nonce, and it is worth slowing down on, because it is the mechanism that turned trust into theft. A normal Solana transaction includes a recent blockhash, a reference to a block from the last couple of minutes. The network rejects the transaction once that blockhash ages out, usually within about ninety seconds. That is a safety feature: it means a transaction you sign now cannot be quietly held and replayed against you weeks later.
A durable nonce removes the expiry. Instead of a recent blockhash, the transaction references a stored nonce account whose value changes only when it is deliberately advanced. A transaction built this way can be signed today and stay valid indefinitely, until someone chooses to broadcast it. The feature exists for legitimate reasons, such as coordinating multisig signers who are not online at the same moment. In the Drift attack it did something else entirely.
Between roughly 23 and 30 March, the attackers induced Security Council members to sign a set of durable-nonce transactions that, in TRM Labs’ description, “appeared routine but carried hidden authorizations.” The signers believed they were approving ordinary governance actions. What they were actually doing was pre-signing the exact instructions that would later transfer the admin key, whitelist a fake collateral token and raise withdrawal limits. The signatures then sat dormant, perfectly valid, waiting for 1 April. This is the clear-signing problem in its most expensive form: when a signer cannot see precisely what an instruction will do, approval becomes a blank check. HOGE Wire has traced how the industry is trying to fix that at the wallet layer in its look at account abstraction and the smart wallet’s new middlemen.
A Two-of-Five Multisig With No Timelock
The pre-signed transactions were only half the setup. The other half was a governance change that shrank Drift’s own defenses days before the attack. In the final week of March, the Security Council migrated to a two-of-five multisig, meaning any two of its five signers could authorize a privileged action. At roughly the same time it removed its timelock, the enforced delay between when a privileged transaction is approved and when it can actually execute.
Timelocks are unglamorous, and they are also one of the most effective safety mechanisms a protocol has. A delay of even a few hours gives the community, and the protocol’s own monitoring, a window to notice a malicious or mistaken instruction and respond before the money moves. Chainalysis is blunt about what the removal cost Drift: a “zero timelock” eliminated the detection window entirely. Combined with a threshold of only two signatures, it meant the pre-approved instructions could fire the instant the attacker broadcast them, with no pause in which anyone could step in.
None of this was a bug. Every one of these settings was a legitimate configuration choice, made by the protocol’s trusted operators, for reasons that presumably made sense at the time. That is precisely the point Halborn and its peers keep returning to. An auditor reading Drift’s Rust programs would have found functions that behaved correctly. The danger lived in the configuration of who could call them and how fast, and that configuration is not what a smart-contract audit examines.
CarbonVote Token: A Few Thousand Dollars Dressed as Hundreds of Millions
With the admin key captured and withdrawal limits lifted, the attacker still needed a way to turn his new authority into other people’s assets. The instrument was a token he had created himself. On 11 March he minted CarbonVote Token, ticker CVT, with a supply of 750 million, and kept the overwhelming majority of it. On its own, CVT was worthless. The trick was making Drift believe otherwise.
To do that, the attacker set up a thinly funded pool on the Solana DEX Raydium, seeded with only a few thousand dollars, and wash-traded CVT against himself to manufacture a price history that held near one dollar per token. Drift’s price oracle, reading that pool, reported the inflated figure to the protocol as though it were a real market quote. The protocol then did what it was designed to do: it treated CVT as collateral worth what the oracle said it was worth, which Chainalysis puts at “hundreds of millions of dollars.”
The rest was arithmetic. Using the privileges the pre-signed transactions had granted, the attacker listed CVT as approved collateral, deposited hundreds of millions of the token at the fake one-dollar price, and borrowed against that phantom balance. He then withdrew the real assets, USDC, JLP, cbBTC and the rest, leaving Drift holding a pile of CVT that could not be sold for anything close to what the protocol had credited it. Oracle manipulation of this kind is an old problem that keeps finding new victims, and it is a reminder that a price feed is only as trustworthy as the market sitting behind it.
A Timeline the Audit Never Saw
Laid out in order, the operation reads less like a software exploit and more like a heist film, with weeks of staging for a payoff measured in minutes.
| Date (2026) | Step | What happened |
|---|---|---|
| Autumn 2025 | Grooming | Attackers pose as a quant trading firm, meet Drift contributors in person and build trust over months |
| 10-11 March | Funding | Attack infrastructure funded with assets withdrawn from the Tornado Cash mixer |
| 11 March | Weaponization | CarbonVote Token (CVT) minted with a 750 million supply, held mostly by the attacker |
| 23-30 March | Pre-signing | Security Council signers tricked into signing durable-nonce transactions carrying hidden authorizations |
| Late March | Weakening | Council migrates to a two-of-five multisig and removes its timelock |
| 1 April, 16:05:18 UTC | Takeover | A pre-signed transaction proposes transfer of the admin key; a second approves it one second later |
| 1 April | Drain | CVT listed as collateral, limits raised, 31 withdrawals remove an estimated $285 million |
| 1 April, hours later | Laundering | Stolen assets bridged to Ethereum, largely as USDC |
16:05 UTC: The Drain Itself
The execution was almost anticlimactic next to the months of preparation. At 16:05:18 UTC on 1 April, the attacker broadcast the first pre-signed transaction, proposing to move Drift’s admin authority to an address under his control. At 16:05:19 UTC, one second later, the second signature executed the transfer. There was no timelock to wait out and no further approval to chase, because both had already been arranged. In the space of a single second, the protocol had a new owner.
From there the privileged actions ran in sequence: list CVT as collateral, raise withdrawal limits, deposit the fake token, withdraw the real one. Halborn and TRM Labs both clock the core of the drain, the thirty-one withdrawals that carried out the bulk of the $285 million, at roughly twelve minutes. Chainalysis, tracing the full arc of on-chain activity including the cleanup and the first bridging hops, times the broader episode at about two and a half hours, ending near 18:31 UTC. Either way, the decisive move was over before most people watching Solana had seen a single alert.
Speed is the recurring signature of these operations. There is no negotiation phase, no probing, no lateral movement you might catch on a dashboard. Everything that could be done slowly and quietly was done in advance, offline, in conversations and dormant signed transactions. What hit the chain was the irreversible part, compressed into minutes so that detection and response had almost nothing to work with.
What an Audit Would, and Did, Miss
This is the uncomfortable center of the Drift story, and the reason a security firm like Halborn keeps writing up incidents it did not cause. A smart-contract audit is a review of code: it looks for logic errors, unsafe math, missing access checks and the other ways a program can be made to misbehave. Drift’s programs, by every available account, did not misbehave. They enforced their rules faithfully against inputs that had been poisoned upstream, by a captured key and a lying oracle.
CertiK co-founder Ronghui Gu put the lesson of 2026 in one sentence, speaking to Forbes about this exact category of attack: a protocol “can pass a flawless code audit and still lose millions because of a compromised admin key.” Rival firms differ on many things, but not on this. The artifacts an auditor signs off on, the contracts themselves, are increasingly not where the money is lost. By CertiK’s count, cumulative 2026 losses had crossed $1.3 billion by late summer, with wallet and key compromise the single costliest category, ahead of contract bugs.
The table below maps the gap. On one side is what a standard code audit covers. On the other is what the Drift attacker actually used. The two barely overlap.
| In a standard code audit | What the Drift attacker used |
|---|---|
| Contract logic and math | Months of in-person social engineering |
| Access-control checks in code | A two-of-five multisig with its timelock removed |
| Reentrancy and overflow risks | Durable-nonce transactions signed weeks in advance |
| Known vulnerable patterns | A wash-traded oracle price on a fake token |
| A snapshot of the code at one moment | A governance configuration changed days before the attack |
This is not an argument that audits are pointless. They remove a whole class of bugs that would otherwise be exploited, and protocols that skip them tend to find out why they should not have. It is an argument that an audit is necessary and nowhere near sufficient, and that treating a clean report as a guarantee of safety is how a protocol ends up surprised.
Halborn’s Autopsy and the Coroner’s Trade
Halborn did not audit Drift’s final deployment, and it is not the protocol’s security vendor. Its role in this story is the one it has quietly built into a franchise: the coroner who arrives after the incident and explains, in public and in detail, how the victim died. Its “Explained” series, which includes a dedicated write-up of the Drift hack and a monthly round-up of the biggest DeFi exploits, has become a reference point for the industry precisely because the firm is willing to say when the code was not the problem.
The firm is well placed to make that call. Founded in Miami in 2019 by Steven Walbroehl and Rob Behnke, bootstrapped for roughly three years and then backed by a $90 million Series A led by Summit Partners in July 2022, Halborn built its name on offensive security rather than box-ticking. It named Jacques Boschung chief executive in 2024 as it pushed toward banks and tokenized assets, with Walbroehl staying on as chief technology officer and Behnke as co-founder and executive chairman. Its service lines, listed on its own site, run from smart-contract assessment and code audits through to red-team exercises, cloud and web-application penetration testing, and AI red teaming, the practice of attacking a system the way a real adversary would. Its stated mission is “to identify and rectify vulnerabilities in blockchain applications, ensuring the safety and integrity of blockchain projects at every stage of development,” and its client page names Coinbase, Polygon and Solana.
That offensive DNA is why Halborn’s reading of Drift carries weight. A firm whose day job is breaking into systems knows that the weakest point is rarely a line of code. Walbroehl warned last year that the human layer is where the fight is moving. Hackers, he told Cointelegraph, are using AI to create “highly personalized, context-aware attacks that bypass traditional security awareness training.” The Drift con, with its months of in-person rapport-building, is exactly that threat without the automation; the automation is what comes next.
When recovery is on the table, Halborn works the problem alongside the blockchain-analytics firm Chainalysis, a partnership the two announced in 2023 to pair preventative security with investigative tracing and fund recovery. In the Drift case, as in most cases involving this particular adversary, there was very little to recover.
Follow the Money: Bridged, Mixed, Gone
The laundering began almost immediately. Within hours of the drain, the stolen assets were being bridged from Solana to Ethereum, moving in chunks of hundreds of thousands and, more often, millions of dollars, and largely converted into USDC along the way. The attack infrastructure itself had been funded in the opposite direction weeks earlier, with assets pulled out of the Tornado Cash mixer on 10 and 11 March, a detail investigators read as consistent with a state-backed operation that treats laundering as a standing capability rather than an afterthought.
Recovery, in the Drift case, was effectively nil. There was no cooperative white-hat return, the outcome protocols sometimes negotiate when the thief is an opportunist who can be bought off with a bounty and frightened with a lawsuit. That route only works when the attacker is willing to talk. When the attacker is working for a sanctioned state, as investigators believe here, the money is not for sale; it is revenue, and it keeps moving. The economics of clawing stolen crypto back, and how rarely it happens once funds leave a centralized chokepoint, is a subject in its own right, one HOGE Wire has mapped alongside the bounty markets that try to beat the thieves to the exit in its guide to bug bounty payouts on Solana and Move.
The absence of a code bug also removed the usual remediation. After a smart-contract exploit, a protocol can patch the flaw, redeploy and tell users the hole is closed. After Drift, there was no flaw to patch. The fixes were procedural: restore timelocks, rethink how signers verify what they are approving, tighten which tokens can ever be listed as collateral, and treat the Security Council itself as a target that needs defending, not merely a control that needs configuring.
A North Korean Signature
Attribution in these cases is rarely a courtroom certainty, and investigators were careful to frame it as a strong read rather than a verdict. But the read was consistent. TRM Labs assessed the Drift hack as the work of North Korean operators tied to the Lazarus Group, the same cluster behind a string of the largest thefts in crypto’s history. The tradecraft fit: the patient social engineering, the durable-nonce signing, the immediate bridging and mixing, and a target chosen for size rather than ideology.
The scale of that single actor’s dominance is hard to overstate. In a report at the end of April, TRM found that North Korea accounted for 76 percent of all crypto hack value stolen in 2026 to that point, roughly $577 million, and that nearly all of it came from just two operations: Drift at $285 million and Kelp DAO at $292 million seventeen days later. The firm put the regime’s cumulative crypto theft since 2017 at more than $6 billion. Two heists, one adversary, three quarters of a year’s losses.
Redbord framed the trend not as a wider net but a sharper one. “What we are watching is not a North Korean campaign that is broader, it is one that is sharper,” he said. “North Korea is moving faster and more precisely than ever.” The precision is the point. These are not spray-and-pray phishing waves; they are targeted operations against specific high-value protocols, with months of preparation and a human angle engineered for each mark. That is a far harder thing to defend against than a bug, because the vulnerability is a relationship, and relationships do not appear in a code diff.
The Pattern Only Sharpened: From Drift to Bitget
If Drift had been an isolated spike, it might have been written off as a one-time masterpiece. It was not. The rest of 2026 made it look like a template. Across the industry the headline losses kept coming from the control plane rather than the contracts, and the totals kept climbing.
September was the cruelest stretch. On 6 September a roughly $320 million exploit hit a Bitcoin sidechain used by exchanges, one of the year’s largest. Then, on 24 September, the exchange Bitget disclosed that attackers had stolen $351.6 million from its hot and warm wallets after compromising a backend system to spoof transaction data and bypass authorization, spreading the theft across Ethereum, BNB Chain, Arbitrum, Avalanche, Optimism, Base and the XRP Ledger. Bitget chief executive Gracy Chen said the method was highly consistent with known North Korean patterns, paused withdrawals, and said losses would be covered by the exchange’s user-protection fund, which holds more than $464 million. It was, by a margin, the largest crypto theft of the year.
The Bitget breach pushed North Korea’s 2026 crypto haul past $1 billion for the year, by Bloomberg’s accounting, and by TRM’s reckoning the regime was responsible for around three quarters of all crypto stolen in 2026. Few of the biggest 2026 thefts, from Drift to Bitget, turned on the kind of smart-contract vulnerability an audit is built to catch. They turned on signatures, keys, backends and people. That is the throughline, and Drift is where it became impossible to ignore. The year’s biggest losses line up as a catalogue of that new attack surface, and the common thread is not a bad line of application code.
Set side by side, the scale of the shift is obvious.
| Incident | Date | Loss | What broke |
|---|---|---|---|
| Drift Protocol | 1 Apr 2026 | ~$285M | Pre-signed governance transactions, fake oracle collateral |
| Kelp DAO | 18 Apr 2026 | ~$292M | Cross-chain messaging configuration and infrastructure |
| Bitcoin sidechain exploit | 6 Sep 2026 | ~$320M | Protocol-level flaw on an exchange-facing network |
| Bitget | 24 Sep 2026 | ~$351.6M | Backend compromise spoofing transaction data |
For comparison, the picture across all of 2025 was already pointing this way. Chainalysis tallied more than $3.4 billion stolen over the year, with North Korea alone accounting for about $2.02 billion of it, a total inflated by the single $1.5 billion Bybit theft in February 2025, itself an attack that subverted a signing interface rather than a contract. The line from Bybit to Drift to Bitget is a lesson the industry keeps relearning at ever higher prices: owning the signer beats breaking the code.
Defending the Control Plane
If the vulnerability is the control plane rather than the code, the defenses have to move there too. None of the measures that would have blunted the Drift hack are exotic; most are things the protocol had and gave up, or had and did not enforce. The lessons security firms drew from the incident cluster into a short, unglamorous list.
- Keep the timelock. A delay between approval and execution is the single cheapest way to buy a detection window. Removing it, as Drift did days before the attack, removes the chance to react.
- Make signers read what they sign. Clear-signing, where a wallet shows the human-readable effect of a transaction rather than an opaque blob, is the direct answer to a pre-signed instruction with hidden authorizations.
- Treat durable nonces as privileged. A transaction that never expires is a loaded weapon left on a table; signing one should trigger far more scrutiny than a routine, expiring transaction.
- Gate collateral listings hard. A token with a few thousand dollars of real liquidity should never be listable as collateral worth hundreds of millions, whatever an oracle reports; sanity bounds and manual review of new assets matter.
- Defend the signers, not just the keys. If the attack comes through a months-long relationship, the people on the Security Council are part of the attack surface, and operational security, verification rituals and red-team testing of the humans belong in the threat model.
There is a harder structural point underneath the checklist. No regulator in the United States mandates a smart-contract audit, accredits the firms that perform them, or sets standards for how a protocol’s keys and governance should be run. The Securities and Exchange Commission under chair Paul Atkins has spent 2026 reworking how tokens are classified, not how code or control planes are secured, which leaves reputation as the only thing policing quality. That is also why the autopsy matters so much: in the absence of a regulator, the public post-mortem is the closest thing the industry has to an accountability mechanism, and firms like Halborn have turned it into both a public service and a marketing channel.
The deeper takeaway from Drift is a reframing of what security even means for a protocol that has already shipped clean code. The audit is the floor, not the ceiling. The adversary that matters most in 2026 is patient, well-funded, state-backed and increasingly armed with AI that can scale the one attack that still reliably works: convincing a human to approve something. Walbroehl’s warning about context-aware attacks that slip past training is not a forecast; Drift is what it looks like in practice. The protocols that survive the next version of this will be the ones that assume their code is fine and spend their paranoia on everything around it, the keys, the config, the oracles, and the people holding the pen.
Frequently Asked Questions
How much was stolen in the Drift Protocol hack?
About $285 million was drained on 1 April 2026, more than half of Drift’s total value locked. At the time it was the largest crypto exploit of 2026 and the second-largest in Solana’s history, behind only the 2022 Wormhole bridge hack.
Was the Drift hack caused by a smart-contract bug?
No. Drift’s contracts behaved as written. The attacker socially engineered the Security Council into pre-signing durable-nonce transactions, captured the admin key, and used a wash-traded fake token as collateral to drain real assets. A standard code audit does not examine key management or governance configuration.
What is a durable nonce and how was it used?
A durable nonce is a Solana feature that lets a transaction stay valid indefinitely instead of expiring after about 90 seconds. The attackers tricked signers into signing durable-nonce transactions weeks early that carried hidden authorizations, then broadcast them on 1 April to seize control.
Who was behind the Drift Protocol hack?
TRM Labs and other investigators attributed it to North Korean operators tied to the Lazarus Group. By late April, Pyongyang accounted for about 76 percent of 2026 crypto hack value, largely from Drift and the Kelp DAO hack that followed it.
What was Halborn’s role in the Drift hack?
Halborn, a blockchain-security firm, did not audit Drift’s final deployment but published one of the detailed public autopsies through its Explained series. Known for offensive security and incident analysis, it works with Chainalysis on fund tracing and recovery.
By Anneke de Vries, senior security correspondent at HOGE Wire.