The Drift Protocol exploit is linked to the DPRK Lazarus Group, which also performed the Bybit and Ronin Bridge hacks, the biggest in crypto space.The Drift Protocol exploit is linked to the DPRK Lazarus Group, which also performed the Bybit and Ronin Bridge hacks, the biggest in crypto space.

Analysts implicate North Korea's Lazarus hacker group in Drift Protocol exploit

2026/04/03 19:35
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

The analysis of Drift Protocol’s recent exploit pointed to North Korean hackers, possibly the same group that exploited Bybit for over $1.4B. The exploit affected multiple DeFi apps across the Solana ecosystem. 

Drift Protocol analysis shows the exploit was possibly performed by North Korea’s Lazarus Group, the same threat actors behind Bybit and the Ronin bridge hack. 

Analysts implicate North Korea's Lazarus hacker group in Drift Protocol exploit

New facts about the exploit are also emerging, based on DivergSec analysis and reports by Elliptic and TRM Labs. 

The attacker did not just compromise the Drift Protocol multisig once. Drift migrated some of its multisig wallets to new Security Council members. Within three days, the attacker compromised the new multisig and prepared with pre-signed transactions on March 31, a day before the attack.

The specific usage of wallets points to the Lazarus Group modus operandi, with a wallet first funded by Tornado Cash, rapid multi-chain bridging to ETH, and consolidating the funds for mixing. 

Based on Elliptic’s research, Lazarus has performed 18 attacks in the year to date. Researchers will cooperate with the Drift Protocol team to track the funds. 

Drift Protocol sends message to exploiters

Drift Protocol announced that critical information about the involved parties has been discovered. The team sent messages to the four identified wallets currently holding the proceeds of the hack. 

The message suggested Drift Protocol may have known the identity of the hackers. The community speculates about possible insider access or project infiltration. Despite this, Drift Protocol was still criticized for having a zero timelock on protocol-level changes, allowing the exploiter to drain liquidity immediately.

Drift Protocol spread contagion to the Solana economy

Drift Protocol retains $232M in value locked, down from over $550M. Multiple protocols that used Drift for yield have had their funds stolen or frozen in whole or in part. 

SOL recovered above $80 after a brief dip in response to the hack. 

The hack affected Reflect Money for its USD+ farming yield. DeFi Carrot lost 50% of its TVL in Drift, and CRT tokens were also affected. Ranger Finance was exposed through rUSD. PiggybankFi lost $106K from deposits into Drift Protocol. 

Project0 paused loans against Drift vaults. Other projects, including Pyra, which lost all its funds, and XPlace, which mainly used Drift for yield. Elemental DeFi was only exposed through a USDC vault. 

Some of the protocols only had their funds on hold until security is improved. Eleven projects were affected so far, not counting the general sentiment repercussions and loss of trust in DeFi lending. 

A total of 35 DeFi protocols have been exploited in 2026 to date, with an accelerating trend and more organized attacks. 

Around $453M was extracted from DeFi, showing it is still a high-risk sector. The hacks undermine the narrative that DeFi would be a suitable way to gain yield with minimal risk. 

If you're reading this, you’re already ahead. Stay there with our newsletter.

Market Opportunity
Drift Protocol Logo
Drift Protocol Price(DRIFT)
$0.0398
$0.0398$0.0398
+0.50%
USD
Drift Protocol (DRIFT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Coinbase CLO: Clarity Act Deal on Stablecoin Yield ‘Very Close’

Coinbase CLO: Clarity Act Deal on Stablecoin Yield ‘Very Close’

The post Coinbase CLO: Clarity Act Deal on Stablecoin Yield ‘Very Close’ appeared on BitcoinEthereumNews.com. In brief Coinbase Chief Legal Officer Paul Grewal
Share
BitcoinEthereumNews2026/04/02 19:54
South Korea Stablecoin Legislation: FSC Accelerates Crucial Regulatory Framework and Tax Review

South Korea Stablecoin Legislation: FSC Accelerates Crucial Regulatory Framework and Tax Review

BitcoinWorld South Korea Stablecoin Legislation: FSC Accelerates Crucial Regulatory Framework and Tax Review SEOUL, South Korea – March 2025 – South Korea’s Financial
Share
bitcoinworld2026/04/02 18:20
How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!