Top StoriesBearish
95
ETHSOL

Drift Protocol Exploited for $280M, Onchain Messages Sent

Solana-based Drift Protocol suffered a $280M exploit, with attackers using pre-signed malicious transactions. Drift sent onchain messages to the exploiter's wallets, while an unknown party demanded 1,000 ETH. The attack affected over 20 protocols, with no recovery yet and potential North Korea links.

CointelegraphCointelegraph by Helen Partz

Quick Take

1

Drift protocol loses $280-286 million in highly sophisticated Solana exploit.

2

Attacker used durable nonces to pre-sign transactions, mirroring Bybit hack technique.

3

Drift sent onchain messages to four attacker wallets seeking communication.

4

Unknown sender demands 1,000 ETH from exploiter; over 20 protocols impacted.

Market Impact Analysis

Bearish

Major exploit causing loss of trust and potential sell-off in SOL and affected tokens.

Timeframeshort

Speculation Analysis

Factuality90/100
RumorsVerified
Speculation Trigger85/100
MinimalExtreme FOMO

Key Takeaways

  • Drift Protocol lost up to $286 million in a sophisticated exploit leveraging Solana's durable nonces feature.
  • The attacker pre-signed malicious transactions weeks in advance, mirroring the Bybit hack methodology.
  • Drift sent onchain messages to four attacker wallets, while an unknown party separately demanded 1,000 ETH from the exploiter.
  • At least 20 Solana protocols were impacted, with Gauntlet alone facing $6.4 million in losses.
  • No funds have been recovered 48 hours after the attack, and North Korean involvement is suspected.
Total Stolen$280M–$286MEstimated range
Protocols Affected20+Solana ecosystem
Ransom Demand1,000 ETHBy unknown sender
Time Elapsed48 hoursNo recovery yet

What Happened

Drift Protocol, a Solana-based DEX, was drained of up to $286 million in a premeditated attack. The team responded by publishing onchain messages to four Ethereum wallets associated with the exploiter, requesting communication via Blockscan chat. Simultaneously, an unidentified party using the ENS name readnow.eth sent a separate onchain message demanding 1,000 ETH, claiming to know the attacker's identity. The exploit has since cascaded across the Solana ecosystem, with over 20 protocols reporting related losses.

The Numbers

The exploit's scale is staggering: $280 million to $286 million vanished in a single operation. Gauntlet, a DeFi platform, absorbed a $6.4 million hit, while the unknown sender's 1,000 ETH demand adds extortion to the theft. Two days have passed without recovery, and the damage keeps mounting as security firm Cyvers warns the impact is still growing across Solana's lending and trading protocols.

Why It Happened

The attacker weaponized Solana's durable nonces, a feature that allows pre-signing transactions for later execution. By embedding malicious instructions days in advance, the exploiter tricked signers into unknowingly authorizing the drain. This closely mirrors the Bybit hack, where similar transaction-spoofing techniques were used. Cyvers described it as a weeks-long staged operation, and some analysts suspect North Korean involvement, though those links remain unverified.

Broader Impact

The incident exposes systemic risks in Solana's transaction architecture and raises red flags about durable nonce abuse. With 20 protocols collateral damage, contagion fears are spiking. This could accelerate calls for additional security layers and may trigger greater scrutiny from regulators and institutional participants eyeing DeFi exposure.

What to Watch Next

  • Whether Drift's onchain outreach leads to partial fund recovery, echoing the Euler Finance hack resolution.
  • Centralized exchange and stablecoin issuer blacklists if the attacker attempts to move funds.
  • Solana Foundation's protocol-level response and potential mitigations for durable nonce vulnerabilities.
Source: Cointelegraph

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Cointelegraph
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

🏛️
Institutional & Investment NewsBullish
83

BlackRock-Backed Securitize Nears NYSE Listing After SEC Nod

Securitize, backed by BlackRock, received SEC approval for its SPAC merger, moving closer to a NYSE listing. The tokenization firm powers major products like BlackRock's BUIDL fund and is helping the NYSE build its tokenized securities platform, highlighting the sector's rapid growth beyond $30 billion.

85% confidence
Jun 5, 2026, 4:46 PM UTC · CoinDesk