Drift Protocol Loses Over $270 Million in Exploit of Solana's Durable Nonces Feature

Here's what it means for you.
If you’re involved in decentralized finance, this incident underscores the importance of security protocols and the potential risks of social engineering attacks.
Why it matters
This exploit highlights systemic vulnerabilities in decentralized finance platforms, raising concerns about user security and trust in the DeFi ecosystem.
What happened (in 30 seconds)
- On April 1, 2026, attackers drained over $270 million from Drift Protocol by exploiting the durable nonces feature through social engineering.
- The attack was facilitated by pre-signed transactions from members of the Drift Security Council, who unknowingly approved malicious actions weeks prior.
- Drift Protocol has paused operations and is investigating the incident while safeguarding its insurance fund assets.
The context you actually need
- Durable nonces are designed for convenience, allowing indefinite transaction validity, which can be exploited if not properly secured.
- Drift Protocol is a decentralized finance platform that offers various trading and lending products, governed by a multisig model requiring multiple approvals for transactions.
- This incident follows a trend of social engineering attacks in DeFi, with previous exploits on platforms like Bybit and Ronin Bridge, emphasizing operational risks over code vulnerabilities.
What's really happening
On March 23, 2026, four durable nonce accounts were established, with two linked to legitimate members of the Drift Security Council and two controlled by the attackers. This setup secured initial signatures that would later facilitate the exploit. Following a migration of the Security Council on March 27, a new durable nonce account was created by March 30, which re-secured the two-of-five approval threshold necessary for executing transactions.
On April 1, just before noon ET, a legitimate test withdrawal from Drift's insurance fund occurred. This was a critical moment, as it set the stage for the attackers to act. They submitted pre-signed transactions two slots apart: first, they created and approved a malicious admin transfer instruction, and then executed it to seize control of the protocol. This allowed the attackers to deploy a fraudulent withdrawal mechanism that drained deposits across various borrow-lend products, vaults, and trading funds in less than a minute.
The durable nonces feature, intended to enhance user experience by allowing transactions to remain valid indefinitely, became the Achilles' heel in this scenario. The attackers exploited the feature's design, which bypassed standard multisig safeguards that would typically prevent unauthorized access. This incident serves as a stark reminder of the operational risks that come with innovative DeFi features, particularly when human error and social engineering are involved.
As the investigation unfolds, the implications for the broader DeFi landscape are significant. The incident not only raises questions about the security of multisig governance models but also highlights the need for enhanced user education regarding social engineering tactics. The rapidity with which the funds were drained underscores the urgency for protocols to implement more robust security measures and for users to remain vigilant against potential scams.
Who feels it first (and how)
- DeFi Users: Individuals holding assets in Drift Protocol may face significant financial losses.
- Investors in Drift Protocol: Stakeholders and investors will see the value of their holdings plummet, with the DRIFT token price collapsing by over 40-98%.
- Security Professionals: Those in the cybersecurity and blockchain security sectors will need to reassess the vulnerabilities in DeFi platforms and enhance protective measures.
- Regulatory Bodies: As decentralized finance continues to grow, regulators may feel pressure to impose stricter guidelines to protect users from such exploits.
What to watch next
- Investigative Outcomes: The results of Drift Protocol's investigation will reveal how the exploit occurred and what measures will be implemented to prevent future incidents.
- Market Reactions: Watch for shifts in the DeFi market, particularly in user trust and investment in platforms that demonstrate robust security measures.
- Regulatory Developments: Increased scrutiny from regulators could lead to new guidelines for DeFi platforms, impacting operational models and user protections.
Over $270 million was drained from Drift Protocol due to a social engineering attack exploiting durable nonces.
Other DeFi platforms may face increased scrutiny and pressure to enhance security measures in light of this incident.
The long-term impact on user trust in DeFi protocols and how quickly they can recover from such a significant exploit.
This article was generated by AI from 3 verified sources and reviewed by A47 editorial systems.
Frequently Asked Questions
- Why it matters?
- This exploit highlights systemic vulnerabilities in decentralized finance platforms, raising concerns about user security and trust in the DeFi ecosystem.
- What happened (in 30 seconds)?
- On April 1, 2026, attackers drained over $270 million from Drift Protocol by exploiting the durable nonces feature through social engineering. The attack was facilitated by pre-signed transactions from members of the Drift Security Council, who unknowingly approved malicious actions weeks prior. Drift Protocol has paused operations and is investigating the incident while safeguarding its insurance fund assets.
- What's really happening?
- On March 23, 2026, four durable nonce accounts were established, with two linked to legitimate members of the Drift Security Council and two controlled by the attackers. This setup secured initial signatures that would later facilitate the exploit. Following a migration of the Security Council on March 27, a new durable nonce account was created by March 30, which re-secured the two-of-five approval threshold necessary for executing transactions. On April 1, just before noon ET, a legitimate te
- Who feels it first (and how)?
- DeFi Users: Individuals holding assets in Drift Protocol may face significant financial losses. Investors in Drift Protocol: Stakeholders and investors will see the value of their holdings plummet, with the DRIFT token price collapsing by over 40-98%. Security Professionals: Those in the cybersecurity and blockchain security sectors will need to reassess the vulnerabilities in DeFi platforms and enhance protective measures. Regulatory Bodies: As decentralized finance continues to grow, regulator
- What to watch next?
- Investigative Outcomes: The results of Drift Protocol's investigation will reveal how the exploit occurred and what measures will be implemented to prevent future incidents. Market Reactions: Watch for shifts in the DeFi market, particularly in user trust and investment in platforms that demonstrate robust security measures. Regulatory Developments: Increased scrutiny from regulators could lead to new guidelines for DeFi platforms, impacting operational models and user protections.
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
How a Solana feature designed for convenience let attackers drain more than $270 million from Drift
A significant exploit on the Solana-based DeFi platform Drift has resulted in attackers draining over $270 million by leveraging a feature known as 'durable nonces.' This allowed pre-signed administrative transfers to bypass the platform's multisig s...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Drift Protocol’s $285m hack exposes social engineering threat to Solana DeFi
Drift Protocol, a decentralized exchange on the Solana blockchain, has suffered a significant exploit resulting in the loss of approximately $285 million, primarily due to social engineering tactics that compromised an administrator key rather than e...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Solana price confirms bearish crossover following Drift exploit, will it crash?
Solana's price has experienced a significant decline of nearly 9%, dropping to an intraday low of $78.6, following a major exploit on the Drift Protocol DeFi platform that resulted in the draining of approximately $300 million in digital assets. This...