Drift Protocol halts operations after suspected $285m exploit as funds move across wallets

ambcryptoPublicado em 2026-04-01Última atualização em 2026-04-01

Resumo

Drift Protocol has halted deposits and withdrawals after confirming an active attack, with initial estimated losses around $285 million. Blockchain security firm PeckShield reported the losses span multiple assets, including $71.4M in USDC and $159.3M in JLP, among others. The attacker has begun moving funds across wallets, likely to obscure transaction trails. Unverified reports suggest the exploit may have involved a compromised administrative key, allowing manipulation of protocol parameters, though this remains unconfirmed. The incident reflects a trend of sophisticated DeFi attacks targeting governance and internal controls. An investigation is ongoing with no timeline for restoring operations.

Drift Protocol has halted deposits and withdrawals after confirming it is experiencing an active attack, with early estimates suggesting losses could reach hundreds of millions of dollars.

The protocol disclosed the incident in a public update on 1 April, stating that it is coordinating with security firms, bridges, and exchanges to contain the situation.

“This is not an April Fools joke,” the team said, adding that further updates will follow as the investigation develops.

Source: X

Estimated losses near $285m as breakdown emerges

Blockchain security firm PeckShield estimated the initial losses at around $285m, based on early on-chain analysis.

A breakdown shared by the firm suggests the exploit spans multiple assets, including:

  • $71.4m in USDC
  • $159.3m in JLP
  • Smaller amounts across USDT, WETH, wrapped BTC, and Solana-based assets
Source: X

While the figures remain preliminary, the scale places the incident among the larger DeFi exploits in recent months.

Funds begin moving across wallets

Separate on-chain tracking indicates that the attacker has already begun moving funds across multiple wallets. This is a pattern typically associated with attempts to obscure transaction trails.

Initial flows suggest assets are being split and transferred through different addresses, with some movements potentially involving cross-chain bridges. This behavior is consistent with past exploits where attackers rapidly redistribute funds to reduce traceability and recovery risk.

At the time of writing, there has been no confirmed recovery of funds.

Unverified reports point to potential exploit mechanism

Unconfirmed reports circulating on social media suggest the attacker may have gained access to a privileged administrative key, allowing them to modify protocol parameters.

According to these accounts, the attacker allegedly manipulated collateral settings, inflated the value of a low-liquidity asset, and used it to borrow higher-value tokens before draining liquidity from the system.

However, these claims remain unverified, and Drift Protocol has not confirmed the attack vector.

A growing pattern of complex DeFi exploits

The incident adds to a broader trend of increasingly sophisticated exploits targeting decentralized finance protocols, where vulnerabilities often extend beyond simple smart contract bugs.

In several recent cases, attackers have exploited governance controls, oracle mechanisms, or internal parameter systems rather than purely external vulnerabilities.

If confirmed, the suspected method in this case would reflect a similar pattern, highlighting how complex protocol design and privileged access controls can introduce new risk surfaces.

Investigation ongoing

Drift Protocol said it is working with multiple partners to investigate the breach and contain further damage. No timeline has been provided for restoring normal operations.

The full scope of the exploit, including the exact attack vector and potential recovery efforts, remains unclear.


Final Summary

  • Drift Protocol has paused operations following an active attack, with early estimates placing losses at around $285m.
  • While funds are already being moved on-chain, the exact exploit method remains unconfirmed as investigations continue.

Perguntas relacionadas

QWhat is the estimated financial loss from the Drift Protocol exploit according to initial on-chain analysis by PeckShield?

AThe estimated financial loss from the Drift Protocol exploit is approximately $285 million.

QWhat specific action did Drift Protocol take in response to the active attack?

ADrift Protocol halted all deposits and withdrawals in response to the active attack.

QWhat is one of the unverified potential mechanisms for the exploit that was circulating on social media?

AUnverified reports on social media suggested the attacker may have gained access to a privileged administrative key, allowing them to modify protocol parameters, manipulate collateral settings, and drain liquidity.

QWhich two assets made up the largest portions of the stolen funds according to the breakdown?

AAccording to the breakdown, the two largest portions of the stolen funds were $159.3 million in JLP and $71.4 million in USDC.

QWhat broader trend in decentralized finance (DeFi) does this incident contribute to?

AThis incident contributes to the broader trend of increasingly sophisticated exploits targeting DeFi protocols, where vulnerabilities often extend beyond simple smart contract bugs to include governance controls, oracle mechanisms, or internal parameter systems.

Leituras Relacionadas

For Hedging, Buy Gold and Oil; For Explosive Growth, Buy AI; Bitcoin, the 'Outdated' Asset, Enters a Bear Market

Bitcoin’s price has recently fallen sharply, hitting a two-month low near $66,000, with Ethereum also dropping to a three-month low. While surface explanations point to ETF outflows, geopolitical tensions, and corporate selling, a deeper issue is emerging: Bitcoin is losing a crucial asset competition. For years, Bitcoin thrived in a low-rate environment where investors sought alternatives amid inflation fears and dissatisfaction with traditional options. Now, the market landscape has shifted, leaving Bitcoin stuck in an "awkward middle ground," facing challenges on three fronts: 1. **As an inflation hedge, gold is winning.** Investors worried about persistent inflation are turning to tangible assets like gold, energy stocks, and commodity producers, which offer more direct pricing power and physical backing. 2. **For growth exposure, AI is winning.** Those seeking high growth now favor AI-related companies with actual revenues and profits, an area where Bitcoin's lack of cash flow puts it at a disadvantage. 3. **Within crypto, infrastructure and stablecoins are winning.** Even investors wanting crypto exposure have alternatives like exchanges, stablecoin issuers, and tokenization firms, whose performance is directly tied to real-world adoption and offers clearer operational leverage. The recent market reaction to inflation warnings highlights this shift. Instead of boosting Bitcoin as "digital gold," such news now drives flows toward traditional inflation-sensitive assets. Therefore, recent events like ETF outflows and corporate selling are seen not as causes, but as symptoms of this new reality. Capital has more compelling options, and investors are becoming more selective. The emerging bear case for Bitcoin is no longer about it being a fraud or failed technology, but rather that **scarcity alone is no longer enough**. It is no longer seen as the best hedge, the best growth asset, or the only crypto play.

marsbitHá 11m

For Hedging, Buy Gold and Oil; For Explosive Growth, Buy AI; Bitcoin, the 'Outdated' Asset, Enters a Bear Market

marsbitHá 11m

SaaS Battle Royale: The Survivors Who Win All Share One Common Trait

**Summary** The AI revolution has triggered a "SaaS apocalypse," forcing a brutal market shakeout. The key dividing line is the pricing model. Companies like Snowflake and Datadog, which charge based on consumption (e.g., data processed or compute used), are thriving. AI workloads actively *generate* more demand for their services, fueling growth. Datadog's accelerating revenue is a prime example. Microsoft and Palantir, as platform/ecosystem players, also benefit by acting as essential channels for AI deployment. In contrast, traditional SaaS firms built on per-seat or per-task licensing (e.g., Intuit, Adobe) face direct pressure, as AI threatens to automate the very human tasks their software supports. Companies like Salesforce, a per-seat giant, are caught in the middle. While showing strong AI monetization (e.g., its Agentforce platform) and experimenting with consumption-based "Flex Credits," its stock remains under pressure, illustrating that the market rewards *completed* transitions, not just the intent. The recent Microsoft Build conference underscored key trends: AI is evolving from an assistant to an autonomous "agent," and platform providers like Microsoft are consolidating their control. The market's recovery is highly selective, focused on identifying which companies are "fed by AI" versus "eaten by AI." Future focus will be on the diffusion of this recovery to transforming companies and the real-world adoption data of AI agents like Microsoft Copilot.

marsbitHá 28m

SaaS Battle Royale: The Survivors Who Win All Share One Common Trait

marsbitHá 28m

Trading

Spot
Futuros

Artigos em Destaque

Como comprar DRIFT

Bem-vindo à HTX.com!Tornámos a compra de Drift Protocol (DRIFT) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Drift Protocol (DRIFT) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Drift Protocol (DRIFT)Depois de comprar o teu Drift Protocol (DRIFT), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Drift Protocol (DRIFT)Transaciona facilmente Drift Protocol (DRIFT) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

270 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar DRIFT

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de DRIFT (DRIFT) são apresentadas abaixo.

活动图片