BREAKING
Sep 29Senate Investigators Checked 846 Sanctioned Iran Wallets. 84% of Them Ran on Tether●Sep 2853 Memecoins on Robinhood Chain Turned Out to Be One Crew. They Took $18.4M, and Each Rug Paid for the Next●Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●Sep 23Circle Pays Binance Every Month to Push USDC. Now Binance Owns $100M of Circle, and the Filing Landed the Same Day the Sanctions Probe Leaked●Sep 22Last Week Manhattan Prosecutors Moved to Seize $61M of Iranian Oil Money That Ran Through Binance. This Week They're Investigating Binance●Sep 21Polymarket's Payment Processor Was Rejecting 80% of US Deposits as Fraud. The CEO's Reported Answer: Keep Growing, Pay the Fine Later●Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-Books●Sep 29Senate Investigators Checked 846 Sanctioned Iran Wallets. 84% of Them Ran on Tether●Sep 2853 Memecoins on Robinhood Chain Turned Out to Be One Crew. They Took $18.4M, and Each Rug Paid for the Next●Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●Sep 23Circle Pays Binance Every Month to Push USDC. Now Binance Owns $100M of Circle, and the Filing Landed the Same Day the Sanctions Probe Leaked●Sep 22Last Week Manhattan Prosecutors Moved to Seize $61M of Iranian Oil Money That Ran Through Binance. This Week They're Investigating Binance●Sep 21Polymarket's Payment Processor Was Rejecting 80% of US Deposits as Fraud. The CEO's Reported Answer: Keep Growing, Pay the Fine Later●Sep 20Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-Books●
BTC -- --%
ETH -- --%
Fear & Greed F&G 73 Greed
ESC
Type to search articles
Solana's Biggest Hack Since Wormhole: $270M Drained From Drift Protocol in Minutes
BREAKING

Solana's Biggest Hack Since Wormhole: $270M Drained From Drift Protocol in Minutes

TL;DR

Drift Protocol, Solana's largest perpetuals DEX, was drained of $270-285M in minutes. The attacker is still bridging funds. It's the biggest Solana hack since Wormhole and a reminder that DeFi security engineering remains critically understaffed.

$270M gone. Not an April Fools joke. The attacker is still bridging funds.

At approximately 4:00 PM UTC on April 1, 2026, Drift Protocol — Solana’s flagship perpetuals and spot DEX — was hit with the largest exploit in the Solana ecosystem since the $325M Wormhole bridge hack in 2022. Between $270M and $285M drained in minutes, and the funds are actively moving right now.

Drift’s own team confirmed it with an almost surreal message: “This is not an April Fools joke.”

What Happened

On-chain investigators Lookonchain and PeckShield flagged suspicious activity originating from Drift’s vaults beginning around 1:30 PM ET. The attack started with a transfer of approximately $155M in JLP tokens from a Drift vault.

Within hours, the attacker’s wallet (HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES) had converted stolen assets to USDC and began bridging from Solana to Ethereum at scale:

  • By 17:49 UTC: 19,913 ETH (~$42.6M) purchased
  • By 18:17 UTC: 38,820 ETH (~$82.66M) accumulated
  • Additional SOL routed through HyperLiquid and direct deposits to Binance

The exploit vector is still unconfirmed — Drift’s team is investigating smart contract vulnerabilities, oracle manipulation, and potentially compromised private keys. No official post-mortem yet.

Drift suspended all deposits and withdrawals immediately. The DRIFT token dropped 20%+ from its intraday high of $0.071.

The Scale of This

The $270M–$285M figure represents roughly 50% of Drift’s total value locked wiped in a single attack. That makes this:

  • The largest DeFi exploit of 2026 by a wide margin
  • The largest Solana ecosystem hack since Wormhole ($325M, February 2022)
  • One of the top 10 DeFi exploits of all time

For context: Drift had been one of the DeFi success stories of the current bull cycle, processing billions in derivatives volume and seen as a serious competitor to Hyperliquid and GMX.

Why This Matters for Crypto Jobs

Events like this reshape hiring across the entire industry — fast.

Immediate demand surge:

  • Smart contract auditors — firms like Trail of Bits, Halborn, Zellic, and Ottersec will see inbound spike. If you have audit experience, now is the time to be visible.
  • On-chain forensics / blockchain analytics — Chainalysis, TRM Labs, and Elliptic will be engaged by Drift and likely by law enforcement. These firms hire aggressively after major exploits.
  • Security engineers — every DeFi protocol watching this is quietly reviewing their own codebase right now. Expect a wave of job postings over the next 2–4 weeks.

Longer-term shifts:

  • Institutional allocators will demand stronger security guarantees before committing capital to DeFi. Protocols that can demonstrate rigorous auditing and formal verification will win that capital — and will hire to maintain that standard.
  • Solana-native security talent is especially scarce. If you have Rust + Solana program audit experience, you are currently very employable.

What gets cut:

  • Protocols directly impacted may face team restructuring or shutdown. Community/marketing roles at Drift are at risk depending on the recovery trajectory.

What Happens Next

Drift has not announced a recovery plan or compensation mechanism yet. The attacker is still actively moving funds across chains, which narrows the window for any coordinated freeze response.

The industry will be watching how this is handled — post-exploit recovery (see: Euler Finance’s $197M hack and negotiated return in 2023) has become a template, but it requires the attacker to be willing to negotiate.

For now: do not deposit into Drift. The team’s official guidance stands.


Sources: Bloomberg, DL News, CoinDesk, Bitcoin News, PeckShield on-chain analysis. Figures unaudited and subject to revision as the post-mortem develops.


Looking for your next role in crypto security, DeFi engineering, or blockchain analytics? Browse open positions at cryptogrind.com — the job board built for Web3 builders.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs