How did hackers siphon $285 million on Solana?
The attack that struck Drift Protocol was no simple smart contract bug. According to initial on chain analyses, the attackers orchestrated a complex manipulation by compromising a protocol admin key. They first created a phantom token, the CarbonVote Token (CVT), before manipulating its price through wash trading to artificially inflate its value.
Once the token was fraudulently listed as a spot market on the DEX, the hackers bypassed the withdrawal limits. By depositing their worthless token as collateral, they managed to drain nearly 20 different vaults. In just 12 minutes, millions of USDC, SOL, and JLP were siphoned off, causing a brutal drop in the protocol’s TVL (Total Value Locked).
Indeed, Drift Protocol announced this Thursday that a malicious actor had taken control of its Security Council. The operation was a formidable combination of pre-signed transactions and multisig approvals (2/5), likely obtained through social engineering or fraudulent misrepresentation.
While the DSOL validator funds and the insurance fund remain out of reach, the entire protocol was frozen as an emergency measure, the compromised multisig was updated, and a massive investigation was launched alongside security firms, exchanges, and authorities.
This latest episode serves as a stark reminder that even on solid technical infrastructures, human governance remains the weakest link in DeFi.
DRIFT token in freefall and Circle does nothing?
The market reaction was swift. Already in a tough spot, the platform’s native token suffered a bloodbath, losing over 38% of its value in the hours following the announcement. This massive selloff reflects a total loss of confidence among liquidity providers, who rushed to close their positions and flee the platform in a panic.

Meanwhile, the hackers wasted no time. Blockchain data shows that the loot was quickly converted via decentralized aggregators before being transferred to the Ethereum blockchain. In total, nearly 129,000 ETH were accumulated by the attackers, a classic maneuver to cover their tracks and avoid asset freezes. This transfer raises serious questions about cross chain security.
Overnight, the renowned investigator ZachXBT made his share of revelations. According to him, Circle stood idle in the face of this massive hack, which raises concerns for the future of the crypto industry:
“Circle sat idle while millions in USDC was bridged via CCTP between Solana and Ethereum from the nine-figure Drift hack during US business hours. Value transferred and once again no action taken.
This comes days after incompetently freezing 16+ active business wallets which are still in the process of being unblocked. Circle, Allaire, you are harming the space,” he wrote.
Will this historic hack impact Solana?
With this colossal theft, Drift Protocol marks the second-largest exploit in the history of Solana, right behind the Wormhole hack in 2022. As the market grows increasingly tense, this event casts a chilling shadow over Solana DeFi. Investors now fear a contagion effect on other protocols.
While Solana has proven its resilience in the past following major crises, the selling pressure on SOL could intensify in the short term. Traders are closely monitoring a potential downside breakout if the key $70 support level breaks under panic. The Drift team’s ability to patch the vulnerability and propose a compensation plan will be decisive for the future.
Sources:
- X – ZachXBT and Drift Protocol
- Tradingview
- AMBCrypto
Related Articles: