Web Analytics
Cryptopolitan
2026-04-02 08:10:32

Drift Protocol hack raises crypto lending red flags as institutional funds chase yields

Drift Protocol, exploited for up to $285M, may have lasting repercussions on Solana DeFi and lending as a whole. The incident exposed significant whale funds, showing the ongoing weakness in Web3 infrastructure. Drift Protocol exposed the weakness of Web3 lending and decentralized trading. The protocol discovered the main cause of the exploit, which was the loss of two private keys to the multisig wallet. This allowed the hacker to change the rules, lock the team out of the admin account, and drain valuable assets against a fake token collateral. Drift Protocol was not exploited through a smart contract, but its governance process was too fast and without failsafe mechanisms. This allowed the hacker to withdraw funds continuously for more than an hour, mimicking borrowing against the posted token collateral . According to OShield Protocol, the compromised wallets allowed the hacker to change the admin key with an on-chain transaction on Solana. Another multisig member, presumably the second compromised key, approved the change. The hacker then created a vault based on a falsely valued token with an inflated oracle price. After that, the hacker was free to use Drift Protocol’s own features for cross-margin and swapping to drain multiple vaults. After the hack, the funds were consolidated on Ethereum addresses in the form of ETH. The hacker used Phantom Wallet , Wormhole bridge and Jupiter’s bridging service to take the funds out of Solana, later using other DEXs to swap out of freezable USDC tokens. The ETH can become hard to trace if mixed through Tornado Cash. On-chain researcher ZachXBT noted Circle did not react to over $230M in USDC while it moved in the early hours after the hack. Update: $230M+ USDC bridged via CCTP from Solana to Ethereum across 100+ txns. 6 hours is how long Circle had to freeze stolen funds from the $280M+ Drift hack. Circle is a centralized stablecoin issuer headquartered in New York and the attack began around 12 pm ET. Why does… pic.twitter.com/v9OKxeOJHN — ZachXBT (@zachxbt) April 2, 2026 In theory, Circle can freeze tokens, but rarely does so, and only if there are legal concerns against a known entity. Which protocols were affected by the Drift Protocol hack? One of the biggest concerns was which other DeFi hubs would be affected by Drift Protocol. The DEX and lending vaults advertised themselves as reliable sources of yield for USDC, just as Solana lending was growing. DeFi Dev Corp., one of the biggest Solana treasury companies, stated it did not get exposure to Drift Protocol. Previously, the DAT company stated it may put some of its funds to use within Solana DeFi vaults, but did not build a direct exposure to Drift. The company still allocates some of its assets to on-chain yield strategies, but has a high standard of risk management. Several smaller DeFi protocols, however, reported indirect losses. In DeFi, vault curation has turned into a tool that sometimes consolidates funds into the largest and presumably, most stable protocols. Before the exploit, Drift Protocol held around $550M in liquidity and was linked to smaller Solana DeFi apps. Protocols include Trade Neutral, Elemental DeFi, SynatraXYZ, Project0, Ranger Finance, and Reflect Money. Carrot Protocol also reported direct losses from funds locked in Drift vaults, an estimated 50% of value locked. After further investigation – Carrot has been impacted by the recent exploit on the Drift protocol. We have paused mint/redeem functions at this time until we can gain more clarity and will update with information when we have it. All Boost and Turbo products are unaffected — Carrot (@DeFiCarrot) April 1, 2026 All user funds were also affected for Pyra Protocol , which was just a storefront for using Drift. The app cannot honor user withdrawals, as all funds were locked with Drift and are completely inaccessible. The exposure of private keys also raises questions about the wider DeFi lending market . Recently, the rise in stablecoin supply and search for yield presented lending as an activity suitable even for institutions. This recent exposure of private keys and admin access hijack showed that Web3 security still has weak spots, which could expose institutional-grade capital to major risks. Following the hack, the overall Solana DeFi value fell from $6.1B to $5.4B , as reported by Defillama. DRIFT tokens also incurred losses, wiping out 37% to a price of $0.04. SOL also lost 5.7% in the past day, sinking below $80. If you're reading this, you’re already ahead. Stay there with our newsletter .

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.