Drift Protocol Hack: Durable Nonces, Admin Capture, and the $250M+ Solana Drain

The Drift Protocol hack was not a generic smart contract bug. It appears to have been a staged admin capture that used durable nonces, privileged state changes, and fast fund extraction to drain more than $250 million.

Summarize with AI

drift-protocol-hack

Drift Protocol Hack: Durable Nonces, Admin Capture, and the $250M+ Solana Drain

A forensic reconstruction of how a Solana perpetuals venue appears to have been captured through privileged approvals, delayed execution, and state reconfiguration rather than a generic trading-engine bug.

Animated Reconstruction

The $250M Drift Hack: Step by Step

Watch each phase of the exploit unfold. Click any node or step indicator to jump directly to that phase.

🎭 ATTACKER Exploiter 1 · HkGz...ES
Exploiter Wallet
Social-engineered admin keys via pre-signed nonce payloads. Orchestrated the entire multi-phase attack.
β†’ Click to jump to Step 1
πŸ›‘οΈ SECURITY COUNCIL Multi-sig signers
Multi-Sig Signers
4-of-6 signers whose keys were captured before the visible drain began.
β†’ Click to jump to Step 1
πŸ”‘ NONCE STAGING 4 durable accounts
Durable Nonce Accounts
4 offline accounts storing pre-signed txns, permanently separating approval time from execution.
β†’ Click to jump to Step 2
⚑ DRIFT ADMIN Security Council powers
Protocol Admin Authority
Upgrade authority silently transferred to attacker. Used to reconfigure oracle trust and collateral rules.
β†’ Click to jump to Step 3
πŸ’° DRIFT VAULT $250M+ JLP
JLP Vault
$250M+ in JLP tokens drained after admin-level safety guards were silently removed.
β†’ Click to jump to Step 5
πŸŒ‰ CIRCLE CCTP Solana β†’ Ethereum
Circle CCTP Bridge
Cross-Chain Transfer Protocol used to move stolen funds from Solana to Ethereum.
β†’ Click to jump to Step 6
πŸ’Ž ETHEREUM Final destination
ETH Receiving Address
Final destination for bridged funds. Cross-chain movement made on-chain containment nearly impossible.
β†’ Click to jump to Step 6

TL;DR

  • The strongest evidence supports an administrative capture, not a public smart contract bug.

  • Drift said the attacker used a durable-nonce-based attack to take over Security Council administrative powers.

  • The clearest exact artifact is a small pre-attack withdrawal from Drift Vault to the attacker wallet, which looks like rehearsal.

  • The CVT theory still fits, but best as a monetization layer after privileged control was already captured.

  • The operational lesson is simple: if admin state controls collateral, oracle trust, and withdrawals, admin workflow is part of protocol security.

Attack at a glance

Four moves explain the incident

The shortest useful model is capture trust, delay execution, reconfigure policy, then extract value.

1

Capture approvals

Signer trust appears to have been compromised before the visible drain began.

2

Use durable nonces

Signed transactions could wait for the attacker's preferred execution window.

3

Reconfigure state

Collateral policy, oracle trust, and withdrawal protections became attacker-controlled surfaces.

4

Bridge out fast

The reported exit route was Solana swaps, Circle CCTP, then Ethereum-side consolidation.

What Is Actually Confirmed

The public record is noisy, but the core facts are not.

Drift said a malicious actor used a durable-nonce-based attack to gain unauthorized administrative access. That matters because Drift's critical controls are not only in trading logic. They also live in privileged state transitions: collateral admission, oracle configuration, market status, exchange status, and withdrawal guards.

If that admin path is captured, the attacker does not need to bypass the system. They can change what the system trusts.

Control map

How the attack likely moved through Drift's control surface

This version treats the exploit as a staged control-system takeover: trust is captured first, delayed execution preserves timing, then privileged state changes turn policy into an extraction path.

1
Stage 1

Capture signer trust

Approvals are obtained or disguised before any visible drain begins.

Entry vector

Signer workflow capture

The attacker gains signed authority without needing to break the public trading engine.

2
Stage 2

Preserve the window

Durable nonces split approval time from execution time.

Execution layer

Durable nonce window

Signed payloads remain live long enough for the attacker to choose the cleanest moment to strike.

Offline signing Delayed broadcast Multi-week prep
3
Stage 3

Take privileged control

This is the pivot: the protocol starts trusting attacker-chosen state.

Privilege pivot

Security Council admin powers

At this point the attacker no longer bypasses defenses. They redefine the defenses.

Oracle trust

Price inputs and accepted feeds can change.

Collateral policy

Borrow power and asset usefulness can be reshaped.

Withdrawal guards

Limits, pauses, and gatekeeping can be weakened.

4
Stage 4

Drain and bridge out

Once policy bends, normal rails become the exit route.

Exit route

Vault drain and bridge-out

Withdrawals, swaps, Circle CCTP, and Ethereum-side consolidation become the visible part of the attack.

Vault outflow Solana swaps CCTP Ethereum
Security model

Why this looks like privileged capture, not a normal DeFi bug

The critical distinction is whether the attacker exploited a public entry point or first gained the authority to change what the protocol accepts as safe.

Typical permissionless exploit
  1. A public code path is flawed.
  2. Any user can hit it directly.
  3. Funds leave through the broken entry point.
Probable Drift path
  1. Privileged approval flow is captured.
  2. Durable nonces preserve delayed execution.
  3. Admin-only state changes land before the drain.

The Durable Nonce Angle

Durable nonces are not the bug. They are the scheduling layer that made the attack harder to detect.

Normal Solana transactions expire quickly because they rely on recent blockhashes. Durable nonce transactions can be signed earlier and executed later. In a governance or council workflow, that means the approval moment and the execution moment can be separated by days or weeks.

Durable nonce window

The dangerous property is delayed execution

When privileged transactions stop expiring quickly, social engineering and delayed execution become much more dangerous.

Normal Solana transaction

Sign Broadcast Expire fast

Approval and execution stay on nearly the same clock.

Durable nonce transaction

Sign early Store Wait Execute later

The attacker gets to choose timing after signatures already exist.

Attack Breakdown

The most defensible reconstruction is not complicated.

Exploit flow

The likely sequence

The best-supported path is capture authority, reshape trust, then monetize.

1

Capture signer context

Approvals are obtained or misrepresented.

2

Stage nonce payloads

Transactions remain executable later.

3

Execute admin instructions

Privileged state transitions land first.

4

Alter trust assumptions

Collateral or oracle policy becomes attacker-friendly.

5

Withdraw real assets

Vault value becomes reachable under the manipulated state.

6

Swap and bridge out

Funds move off-route before containment catches up.

The clearest early proof: a rehearsal withdrawal

The strongest exact artifact recovered in this investigation is transaction:

5brWcBQk4iYGH1YuaA4JYS6QhedA9itA2MDaJixqrhQe9Pk6mzpt2N68Ne5a2nqrgHmg5AxN4RMPH3paqX5jSM8a

Solscan labels it as a withdrawal from Drift Vault JCNCMFXo5M5qwUPg2Utu1u6YWp3MbygxqBsBeXXJfrw to Drift Exploiter 1 HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES.

The amount was only 0.03000003 WSOL, but that is exactly why it matters. It reads like a test of the extraction path before the main drain.

Primary evidence Official statement

Drift's own wording sets the frame

Drift described the incident as a durable-nonce-based attack that rapidly took over Security Council administrative powers.

Open Drift's official statement
Exact artifact Pre-attack rehearsal

Small WSOL withdrawal from Drift Vault to attacker

Amount0.03000003 WSOL
FromDrift Vault
ToDrift Exploiter 1

This is the cleanest direct pre-drain proof artifact recovered in the case.

Open the exact Solscan transaction

Why admin capture mattered more than any single downstream trick

Once privileged execution is lost, multiple safety layers become exploitable at once.

Cascade diagram

One privileged path can reshape the whole risk model

Admin capture matters because it converts multiple downstream trust surfaces into attacker-controlled levers.

Root compromise

Admin capture

Security Council or equivalent control path is abused.

Downstream effect

Oracle trust

Which prices the protocol accepts can change.

Downstream effect

Collateral policy

Asset weights and usefulness can shift.

Downstream effect

Withdrawal guards

Limits and pause controls become weaker.

Outcome

Real asset extraction

The drain happens after the policy layer is already bent.

This is why "admin takeover" is the main story. Oracle abuse or fake collateral may have been part of monetization, but they are downstream once the attacker can change trusted state.

Where the CVT theory fits

r0bre's three-transaction claim is still useful:

  1. create a Drift user account

  2. deposit 500 million CVT as collateral

  3. withdraw real assets against that collateral

That is a plausible monetization path because Drift's cross-collateral model explicitly turns approved deposits into usable margin according to policy. But the CVT story does not explain the root cause by itself. The more important question is how the protocol could have been made to trust that asset in the first place.

The best current answer is privileged reconfiguration after admin compromise.

Evidence Map

Evidence map

Exact artifacts versus strong reported leads

First major reported drain
41 million JLP at about $155 million
ConfirmedPublished reporting
Reported by Decrypt from on-chain activity around 11:06 a.m. ET.
Post-exploit route
Solana swaps -> CCTP -> Ethereum
ConfirmedCross-source match
Consistently described by ZachXBT and Lookonchain.
Thread-reported trail

Three abbreviated hashes still matter, but only as leads

These shortened signatures come from public investigator threads. The full Solscan transaction IDs were not published, so they cannot be independently opened and should be treated as directional clues rather than exact evidence artifacts.

Alleged user account creation

Thread-only hash
4xzb1AXSw45...

Reported in public threads as the setup transaction that created a Drift user account before the rest of the sequence.

Alleged 500M CVT deposit

Thread-only hash
5V72ZK1WejP...

Cited as the abbreviated signature for the claimed oversized CVT collateral deposit used in the monetization theory.

Alleged real-asset withdrawal

Thread-only hash
2jCAE2SakEH...

Referenced as the shortened signature for the alleged withdrawal that turned the collateral story into real extracted value.

Fund Flow

The exit path is less disputed than the setup.

Fund flow

Where the funds appear to have gone

Investigators broadly agree on the route even where they differ on root cause details.

1
Route start

Drift vault outflows

Compromised protocol state makes real vault assets withdrawable.

2
Solana layer

Solana-side swaps

Assets are routed into more liquid exit assets before the bridge leg.

3
Bridge prep

USDC concentration

Bridge-friendly value is assembled before leaving Solana.

4
Cross-chain leg

Circle CCTP

Funds move through the clearest publicly reported settlement rail.

5
Route end

Ethereum consolidation

Containment shifts from protocol response to broader ecosystem response.

ZachXBT's main contribution here is containment analysis. The key operational criticism is that funds were still moving in size during U.S. business hours without fast enough intervention across the bridge and issuer surface.

Timeline

Timeline

A staged operation, not a single transaction burst

Confirmed items and plausible items are separated so evidence quality stays obvious.

Mid to late March 2026

Preparation phase

Drift later described a multi-week staged operation consistent with delayed privileged execution.

March 23, 2026

Nonce-account setup is alleged

Third-party reports say four nonce accounts were created. The fit is strong, but the public proof is still incomplete.

Before the main drain

WSOL rehearsal withdrawal lands

The exact rehearsal withdrawal shows the extraction path was already working.

April 1, 2026, 11:06 a.m. ET

First major drain is reported

Decrypt reports roughly 41 million JLP, around $155 million, leaving the protocol.

April 1, 2026, afternoon

Drift pauses deposits and withdrawals

The protocol acknowledges the incident publicly and moves into response mode.

April 1 to April 2, 2026

Swaps, bridging, and consolidation continue

The case becomes a containment problem across Solana, Circle CCTP, and Ethereum.

Chronological sequence

Compact event register

Badges describe evidence quality, not importance: Confirmed means directly observable or officially disclosed, while Reported lead means the claim fits the public record but still lacks complete proof.

Mid-to-late March 2026
Multi-week staged operation begins
ConfirmedOfficial disclosure
This comes directly from Drift's description of the incident.
March 23, 2026
Four nonce accounts allegedly created
Reported leadThread evidence
Fits the durable nonce theory but still needs fuller public proof.
Late March 2026
Attacker wallet appears funded and active
ConfirmedExplorer record
Supports the view that the drain was not improvised on the same day.
Before April 1
Exact WSOL rehearsal withdrawal
ConfirmedPrimary artifact
The cleanest primary artifact in the case.
April 1, 11:06 a.m. ET
About 41 million JLP leaves
ConfirmedPublished reporting
Decrypt pegs the first major visible drain around $155 million.
April 1 to April 2
Swaps, bridging, and consolidation
ConfirmedCross-source match
The route was broadly described as Solana swaps, CCTP, then Ethereum.

Root Cause and Lessons

The root cause was privileged-state compromise.

That phrasing is more useful than "oracle exploit" and more precise than "admin key leak." Drift's published design makes collateral policy, oracle trust, and withdrawal safety dependent on trusted administration. Once that administration is captured, monetization paths multiply.

Three lessons follow:

  1. Multisig thresholds are not enough if signers can approve opaque or delayed payloads.

  2. Governance safety is protocol safety when admin state controls borrow power and withdrawals.

  3. Durable nonce workflows need visibility and alerting, not just permissioning.

{
  "title": "🎬 Admin capture to drain, and how a timelock breaks it",
  "stage": { "width": 920, "height": 440 },
  "nodes": [
    { "id": "attacker", "label": "Attacker", "role": "captures admin", "emoji": "πŸ§‘β€πŸ’»", "x": 60, "y": 200, "color": "red" },
    { "id": "council", "label": "Security Council", "role": "admin powers", "emoji": "πŸ›‘οΈ", "x": 430, "y": 60, "color": "cyan" },
    { "id": "vault", "label": "Drift Vault", "role": "collateral control", "emoji": "🏦", "x": 430, "y": 330, "color": "gold" },
    { "id": "exit", "label": "Exit route", "role": "swaps β†’ CCTP β†’ ETH", "emoji": "πŸŒ‰", "x": 760, "y": 200, "color": "purple" }
  ],
  "links": [
    { "from": "attacker", "to": "council" },
    { "from": "council", "to": "vault" },
    { "from": "vault", "to": "attacker" },
    { "from": "attacker", "to": "exit" }
  ],
  "nets": [
    { "id": "vault", "label": "Vault value" },
    { "id": "atk", "label": "Attacker (off-route)" }
  ],
  "legend": [
    { "cls": "call", "label": "admin instruction" },
    { "cls": "token", "label": "asset movement" },
    { "cls": "sig", "label": "trust / state change" },
    { "cls": "fail", "label": "delayed / blocked" }
  ],
  "scenarios": {
    "What appears to have happened": [
      { "note": "Collateral policy, oracle trust, and withdrawals depend on <b>trusted administration</b> by the Security Council.", "hi": ["council","vault"], "bal": { "vault": "collateral intact", "council": "trusted" }, "net": { "vault": "$250M+", "atk": "$0" } },
      { "note": "The attacker captures Security Council admin powers through the reported durable-nonce takeover.", "tone": "bad", "hi": ["attacker","council"], "chip": { "from": "attacker", "to": "council", "label": "capture admin", "cls": "sig" }, "bal": { "council": "attacker-controlled" } },
      { "note": "With <b>durable nonces</b>, signed admin instructions stay executable until the attacker's chosen window.", "tone": "bad", "hi": ["council","vault"], "chip": { "from": "council", "to": "vault", "label": "durable-nonce admin tx", "cls": "call" } },
      { "note": "A tiny rehearsal withdrawal (<b>0.03 WSOL</b>) tests the extraction path from the vault to the attacker.", "tone": "bad", "hi": ["vault","attacker"], "chip": { "from": "vault", "to": "attacker", "label": "rehearsal: 0.03 WSOL", "cls": "token" } },
      { "note": "Once policy is attacker-friendly, the real vault assets become reachable and are drained.", "tone": "bad", "hi": ["vault","attacker"], "chip": { "from": "vault", "to": "attacker", "label": "drain $250M+", "cls": "token" }, "bal": { "vault": "drained", "attacker": "+$250M+" }, "net": { "vault": "$0", "atk": "+$250M+" } },
      { "note": "Funds are swapped on Solana, concentrated to USDC, and bridged out through CCTP before containment catches up.", "tone": "bad", "hi": ["attacker","exit"], "chip": { "from": "attacker", "to": "exit", "label": "swap β†’ CCTP β†’ ETH", "cls": "token" } }
    ],
    "Fixed (timelock + guardian)": [
      { "note": "The same design routes admin instructions through a <b>timelock</b> with monitoring.", "hi": ["council","vault"], "bal": { "vault": "collateral intact", "council": "timelocked" }, "net": { "vault": "$250M+", "atk": "$0" } },
      { "note": "Even if signer trust is compromised, the captured admin powers can no longer act instantly.", "tone": "ok", "hi": ["attacker","council"], "chip": { "from": "attacker", "to": "council", "label": "capture admin", "cls": "sig" } },
      { "note": "The staged durable-nonce admin tx hits a <b>timelock delay</b>, queues publicly, and triggers monitoring.", "tone": "ok", "hi": ["council","vault"], "chip": { "from": "council", "to": "vault", "label": "⏳ queued (timelock)", "cls": "fail" } },
      { "note": "During the delay, a guardian or pause path revokes the malicious change before reconfiguration lands.", "tone": "ok", "hi": ["council"], "chip": { "from": "council", "to": "council", "label": "guardian revokes", "cls": "sig" } },
      { "note": "Collateral, oracle trust, and withdrawals stay under honest policy. The vault is never made drainable.", "tone": "ok", "hi": ["vault"], "bal": { "vault": "collateral intact" }, "net": { "vault": "$250M+", "atk": "$0" } }
    ]
  }
}

Conclusion

The cleanest summary is this: the attacker does not appear to have broken Drift's math first. The attacker appears to have gained the right to tell Drift what to trust.

That distinction matters. It moves the incident out of the narrow category of trading-engine bugs and into the much larger category of governance, signer, and privileged-workflow failure.

Further study:

Appendix: Confirmed Facts, Disputed Claims, and Unknowns

Confirmed Facts

  • Drift said the attacker gained unauthorized access through a durable-nonce-based takeover of administrative powers.

  • The attacker wallet was HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES.

  • A labeled Drift Vault account sent a small exact WSOL withdrawal to that wallet before the larger drain.

  • More than $250 million appears to have been lost.

  • Post-exploit routing moved through Solana swaps and Circle CCTP toward Ethereum.

Disputed or Partially Verified Claims

  • The precise CVT mint and its exact role in the monetization path.

  • The exact number of compromised or deceived signers.

  • The full list and order of admin-level instructions executed after compromise.

  • The final ETH balance attributed to the exploiter.

Unknowns That Still Matter

  • Which exact signer workflow failed.

  • Whether the approvals were maliciously disguised, device-compromised, or both.

  • Whether any off-chain coordination or infrastructure compromise preceded the nonce phase.

Appendix: Sources