On April 1, 2026, a compromised admin private key enabled an attacker to drain $285 million from Drift Protocol in under one hour β the second-largest exploit in Solana history and the most damaging DeFi hack of 2026.
$285 million stolen in ~60 minutes: Drift Protocol's total vault balance collapsed from $309 million to $41 million on April 1, 2026, as an attacker leveraged compromised admin keys to execute 11 unauthorized transactions draining JLP, USDC, SOL, cbBTC, USDS, wBTC, USDT, and other assets.
Admin key compromise, not a smart contract bug: PeckShield founder Jiang Xuxian confirmed the root cause as a private key leak β one of the oldest and most preventable security failures in crypto β not a novel protocol exploit, re-entrancy flaw, or oracle manipulation.
Second-largest Solana exploit in history: The attack trails only the $326 million Wormhole bridge hack of 2022, placing it among the top ten DeFi exploits globally by dollar value, with immediate implications for institutional risk assessment of the entire Solana DeFi ecosystem.
DRIFT governance token collapsed 20β42%: From a pre-hack price of $0.071, DRIFT fell to as low as $0.0417 during peak panic β already down 98% from its $2.60 all-time high in November 2024 β raising questions about protocol viability and token holder recovery.
Full cross-chain laundering completed within hours: Stolen assets were swapped via Jupiter DEX into USDC, bridged from Solana to Ethereum mainnet, and accumulated as 19,913 ETH (~$42 million equivalent) before exchanges and bridges implemented freezes β demonstrating the speed at which modern DeFi attackers operate.
Drift Protocol launched in 2021 as one of the first fully on-chain perpetual futures exchanges on Solana, offering cross-margined accounts, spot trading, and a JLP-backed vault system that became attractive to yield-seeking depositors. The protocol benefited enormously from Solana's resurgence in 2024β2025: cheap fees, sub-second finality, and a growing meme-coin culture had driven explosive growth in on-chain derivatives activity, with Drift emerging as the flagship perp DEX on the network. By late 2025, Drift v3 had launched with "10x faster trade execution," and the protocol was on pace for $30.75 million in annualized revenue in 2026 β a 193% year-over-year growth trajectory from $14 million in 2024.
The macro backdrop entering April 2026 was one of cautious optimism for Solana DeFi. Total Value Locked across the ecosystem had stabilized after months of post-FTX reputational damage, and Drift's ~$550 million TVL represented roughly 8β10% of total Solana DeFi liquidity. Institutional money had begun re-entering on-chain derivatives, attracted by Drift's professional-grade infrastructure: multi-collateral accounts, sophisticated margin engines, and yield products embedded in the JLP Delta Neutral, SOL Super Staking, and BTC Super Staking vaults. These vaults β the highest-yield products on the platform and therefore the highest-balance components β would become the primary targets on April 1.
The DeFi security landscape in 2026 remained deeply troubled. While smart contract audits had improved and formal verification had gained traction, operational security β specifically, private key management for privileged protocol roles β had not kept pace. Centralized upgrade keys, admin multisigs with weak quorum requirements, and improper secret storage continued to represent the dominant attack surface across the industry. The Drift exploit arrived not as a sophisticated zero-day in cryptography or protocol design, but as a reminder that the most dangerous vulnerabilities are often human ones. At a moment when DeFi was marketing itself to institutions, a $285 million key compromise delivered a crushing rebuke to the narrative of "trustless" finance.
The timing added a layer of cruel irony. April 1 β April Fools' Day β prompted immediate disbelief across crypto social media when the first alerts appeared. The Block's headline captured the sentiment perfectly: "Not an April Fools joke': Major Solana-based trading platform Drift exploited for at least $200 million." Within hours, it became clear the joke was entirely on Drift's 50,000+ depositors.
March 24, 2026 β Attacker wallet created: On-chain forensics later revealed that wallet HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES was created approximately eight days before the attack. The wallet showed brief activity on OKX (likely for initial SOL funding) and executed a few test swaps on Jupiter DEX, then went dormant β a pattern consistent with deliberate staging and reconnaissance.
March 31 β April 1, 2026 (18 hours pre-attack) β Attacker goes active: The attacker wallet resumed activity approximately 18 hours before the main attack, conducting what appear to be final pre-positioning transactions. This window likely corresponds to the moment the attacker confirmed that compromised admin credentials were operational and that vault balances were near peak.
April 1, 2026, 4:00 PM UTC (~11:06 a.m. ET) β Attack begins: The attacker used compromised admin private keys to invoke privileged vault management functions. Unlike flash loan attacks that must be completed within a single block, an admin key compromise grants the attacker unlimited time and the ability to execute sequential, deliberate transactions. Eleven total transactions were recorded. The largest single transfer moved 41.7 million JLP tokens valued at approximately $155.6 million β roughly half the total haul in a single transaction β out of the JLP Delta Neutral vault.
April 1, 2026, ~5:00 PM UTC β Treasury collapses: Within approximately one hour, Drift's vault balances fell from $309 million to roughly $41 million β an 87% drawdown in 60 minutes. Assets drained included JLP, SOL, USDC, cbBTC (Coinbase-wrapped Bitcoin), USDS, wBTC, USDT, Fartcoin, and wETH across all three major vaults.
April 1, 2026, ~3:00 PM ET β Public announcement and protocol suspension: Drift Protocol posted on X: "Drift Protocol is experiencing an active attack. Deposits and withdrawals have been suspended. We are coordinating with multiple security firms, bridges and exchanges to contain the incident." This announcement came approximately four hours after the attack began β a gap that drew criticism from security researchers who noted that automated circuit breakers could have limited losses had they been deployed. Helius CEO Mert Mumtaz was among the first to flag suspicious on-chain activity publicly.
April 1β2, 2026 β Cross-chain laundering: Stolen assets were routed through Jupiter DEX to consolidate into USDC and SOL, then bridged from Solana to Ethereum mainnet. Arkham Intelligence tracked the accumulation of 19,913 ETH (approximately $42 million at prevailing prices) in attacker-controlled addresses on Ethereum. The cross-chain movement complicated asset freezing efforts, as Solana-native USDC issuers (Circle) and bridge operators attempted to blacklist addresses after the fact.
The Drift Protocol exploit is technically classified as a privileged key compromise β categorically different from the smart contract exploits that dominated DeFi headlines in 2020β2023. To understand why this distinction matters, one must understand Drift's vault architecture. Drift v3's yield-bearing vaults β the JLP Delta Neutral, SOL Super Staking, and BTC Super Staking products β were designed for capital efficiency, meaning they held large, concentrated balances in a relatively small number of Solana Program Derived Accounts (PDAs). These PDAs were governed by an admin key that held authority to sign withdrawal and rebalancing instructions on behalf of the protocol.
In a properly secured system, this admin key would be a hardware-secured multisig requiring multiple independent signers (e.g., a 3-of-5 Gnosis Safe equivalent on Solana, using Squads Protocol). The post-exploit analysis from PeckShield, corroborated by independent on-chain researchers, strongly suggested that Drift's admin key either: (a) was stored in a hot wallet or server environment that was compromised through a phishing attack, supply-chain compromise, or insider breach; or (b) had insufficient multisig quorum requirements that allowed a single compromised signer to unilaterally authorize vault withdrawals. The specific mechanism by which the key was obtained has not been publicly confirmed by Drift as of this writing.
Once the admin key was in the attacker's possession, execution was methodical and automated. The attacker's script executed 11 transactions across all three primary vault systems, prioritizing the highest-value vault first: the JLP Delta Neutral vault, which held an estimated $155.6 million in JLP tokens. JLP (Jupiter Liquidity Provider token) is itself a basket of Solana-native assets backing Jupiter's perpetual exchange, making it a deep, liquid instrument that could be swapped to USDC with minimal slippage on Jupiter DEX β which is precisely what the attacker did. Subsequent transactions targeted SOL Super Staking (held staked SOL and liquid staking derivatives) and BTC Super Staking (held cbBTC and wBTC). The attacker also drained protocol-owned USDC, USDS, and Fartcoin reserves.
The cross-chain laundering methodology revealed a sophisticated understanding of on-chain forensics and asset recovery mechanisms. By converting everything to USDC on Solana first, then bridging to Ethereum and converting to ETH, the attacker effectively broke the on-chain audit trail across two ecosystems while converting to a truly non-censorable asset (native ETH, unlike USDC, cannot be frozen by a central issuer). The choice of ETH β rather than, say, further bridging to a privacy chain β suggests the attacker may have been testing whether bridges and exchanges would react quickly enough to freeze funds. In at least this phase, they moved faster than the protocol's incident response.
sequenceDiagram
participant AW as Attacker Wallet<br/>(HkGz4Kmo...)
participant DV as Drift Vaults<br/>(JLP Delta Neutral,<br/>SOL & BTC Super Staking)
participant JX as Jupiter DEX
participant BG as SolanaβETH Bridge
participant EW as Ethereum Wallet<br/>(19,913 ETH)
Note over AW: March 24 β Wallet created
Note over AW: April 1, 3:42 AM UTC β Pre-positioning begins (T-18h)
AW->>DV: Use compromised admin key<br/>to invoke vault withdrawal
DV-->>AW: TX 1: 41.7M JLP tokens (~$155.6M)
DV-->>AW: TX 2β5: SOL, cbBTC, wBTC, USDC
DV-->>AW: TX 6β11: USDS, USDT, wETH, Fartcoin
Note over DV: TVL: $309M β $41M in ~60 mins
AW->>JX: Swap all assets β USDC + SOL
JX-->>AW: Consolidated USDC/SOL
AW->>BG: Bridge USDC + SOL to Ethereum
BG-->>EW: Converted to 19,913 ETH
Note over EW: ~$42M equivalent on ETH mainnet
Note over AW,EW: Cross-chain asset dispersion<br/>complicates freezing effortsMetric | Value | Change | Source |
|---|---|---|---|
Total Stolen | ~$285 million | β | PeckShield |
Drift TVL (pre-attack) | ~$550 million | β | DefiLlama |
Drift TVL (post-attack) | ~$41 million | -93% | DefiLlama / Arkham |
DRIFT Token Price (pre) | $0.071 | β | CoinGecko |
DRIFT Token Price (post, low) | $0.0417 | -41.3% | CoinGecko |
DRIFT All-Time High | $2.60 (Nov 2024) | -98% from ATH | CoinGecko |
24h DRIFT Trading Volume | ~$14.2 million | +840% vs avg | CoinGecko |
Largest Single Transfer | 41.7M JLP = $155.6M | β | On-chain / MEXC |
Attacker ETH Accumulated | 19,913 ETH (~$42M) | β | Arkham Intelligence |
Drift 2025 Protocol Revenue | ~$41 million | +193% YoY | Messari / DeFiLlama |
Drift v3 Launch | December 2025 | β | Drift Blog |
Wormhole 2022 Exploit (ref) | $326 million | β | Historical record |
The TVL collapse from $550 million to $41 million represents a destruction of approximately $509 million in depositor positions β the delta between what was in the protocol and what remains reflects not only direct theft but panic withdrawals from remaining users once the attack became public. The DRIFT token's intraday move from $0.071 to $0.0417 (at the worst) reflects the market's immediate verdict on protocol viability: a 41% single-day decline on top of a preexisting 98% drawdown from the all-time high signals near-total loss of confidence in the near term.
Trading volume in DRIFT surged approximately 840% above the 30-day average during the attack day, as panicked holders liquidated positions and opportunistic traders speculated on a potential recovery or complete capitulation. This volume profile β a sharp spike followed by a declining price β is characteristic of "distribution into panic" dynamics that typically precede prolonged bear phases for affected protocol tokens. The $14.2 million in 24-hour volume, while elevated, also indicates that DRIFT's already-reduced liquidity profile meant many large holders could not exit without significant slippage, compounding losses.

Jupiter Perpetuals (Solana): As Drift's primary on-chain competitor on Solana, Jupiter Perps operates its own JLP-backed liquidity model for perpetual trading. Ironically, Drift's attack routed stolen funds through Jupiter's DEX infrastructure (the Jupiter swap aggregator), highlighting the deep entanglement of Solana DeFi protocols. Jupiter Perps will likely see a short-term TVL increase as displaced Drift liquidity seeks a home, but faces its own key management scrutiny in the post-exploit environment. Jupiter's model benefits from being tightly integrated with the broader Jupiter aggregation stack, giving it more natural liquidity depth β a structural advantage Drift will need to rebuild.
dYdX (Cosmos app-chain): dYdX v4 operates as a sovereign Cosmos chain with a fully decentralized orderbook, offering the most credible alternative for institutional perpetuals traders seeking non-Solana infrastructure. Following the Drift exploit, dYdX's positioning as a "decentralization-maximalist" exchange will be strengthened in institutional narratives β its orderbook model, while gas-heavier to operate, eliminates the centralized vault admin key surface that undid Drift. dYdX's primary weakness is liquidity depth and user experience relative to Solana-native platforms, particularly for retail participants.
GMX (Arbitrum/Avalanche): GMX pioneered the liquidity pool model for perp DEXs (GLP) that Drift's vault system partly mirrors. GMX has survived multiple years of intensive scrutiny, oracle manipulation attempts, and market volatility without a catastrophic key compromise β partly because its contract architecture has been more conservatively governed. GMX's relative maturity and audited history will appear more attractive to risk-averse capital post-Drift. However, GMX's trading UX and fee structure are less competitive for high-frequency Solana-native users.
Hyperliquid (L1): Emerging as the fastest-growing perp DEX in 2025β2026 by volume, Hyperliquid runs a purpose-built L1 with a central limit orderbook and has attracted billions in open interest from traders seeking low-latency execution. Hyperliquid's validator model and key management architecture differ fundamentally from Drift's vault admin pattern, but the platform is not without centralization risk at the validator layer. The Drift exploit will accelerate comparisons between Hyperliquid and Solana-native DEXs, as Hyperliquid's recent growth trajectory positions it to absorb displaced Drift trading volume.
Depositors / Vault Users: The most directly harmed group. Users who held positions in Drift's JLP Delta Neutral, SOL Super Staking, and BTC Super Staking vaults face potential total loss of deposited capital depending on whether a recovery or compensation mechanism is established. Historical precedent (Wormhole 2022, Euler Finance 2023) suggests that some fraction of funds may be recovered through white-hat negotiations, protocol bailouts, or insurance fund deployment β but full recovery is rare. Users who had positions in spot trading accounts rather than vaults may have been less directly affected, as the attack specifically targeted vault contracts.
DRIFT Token Holders: Token holders face a dual risk: direct value destruction from the 41% intraday price decline, and longer-term existential risk if the protocol cannot rebuild TVL and revenue. The token's utility as a governance and fee-sharing instrument is contingent on the protocol operating at scale β a $41 million TVL base generates insufficient revenue to sustain meaningful token economics. DAO treasury depletion (if treasury assets were held in protocol-controlled vaults) could also limit the governance body's ability to fund recovery operations.
Drift DAO / Core Contributors: The team faces immediate legal exposure in multiple jurisdictions. Bloomberg Law's coverage of the exploit signals that regulatory and civil litigation attention is incoming. Questions about whether admin key security met reasonable standards of care, whether users were adequately disclosed to about centralization risks, and whether Drift DAO entities bear fiduciary responsibility for depositor losses will be contested across both US and international legal frameworks. The team's response speed β a ~4 hour gap between attack start and public disclosure β will also be scrutinized.
Solana Foundation / Ecosystem: The second major exploit in Solana ecosystem history (after Wormhole) reinforces negative institutional narratives about Solana's security culture. While the Drift exploit was not a base-layer vulnerability β Solana's consensus and runtime were not implicated β the ecosystem's reputation suffers collectively from high-profile exploits on its applications. Solana Foundation may face pressure to establish a security fund, mandatory audit standards for protocols above a TVL threshold, or an on-chain insurance primitive to prevent future depositor losses at this scale.
Regulators: The Drift exploit will feature prominently in 2026 regulatory discussions around DeFi protocol liability, key management standards, and whether "decentralized" protocols with identifiable admin key holders should be subject to financial institution-grade operational risk requirements. US CFTC jurisdiction over on-chain derivatives may be invoked, given Drift's primary product is perpetual futures. The EU's MiCA framework, which came into full effect in late 2024, has provisions that may apply to protocol operators with EU-accessible interfaces.
Unrecoverable Capital Loss β The $285 million stolen is distributed across multiple wallets on Solana and Ethereum, with a significant portion already converted to native ETH β a non-censorable asset. While Circle can freeze USDC on Solana (and reportedly attempted to do so), the attacker's rapid conversion to ETH means a substantial fraction is effectively unrecoverable without law enforcement action or voluntary return. Severity: Critical. Probability of full recovery: <5%.
Protocol Viability Risk β Drift's TVL at $41 million post-exploit is insufficient to sustain the liquidity flywheel required for a competitive perpetuals exchange. Market makers, institutional LPs, and sophisticated yield depositors will be extremely reluctant to return capital to a protocol that has demonstrated admin key vulnerabilities. Without a credible recovery narrative β including a full public post-mortem, architectural redesign eliminating single-key admin control, and possibly a token-backed recapitalization β Drift faces a multi-year (or permanent) decline from first-tier DEX status. Severity: High. Probability of meaningful recovery within 12 months: ~20β30%.
Legal and Regulatory Exposure β Drift DAO and its identifiable core contributors face civil class action risk from harmed depositors across multiple jurisdictions. Bloomberg Law and FinanceFeeds coverage of the exploit ensures mainstream financial press attention, which historically precedes regulatory inquiries. CFTC enforcement action targeting Drift as an unlicensed derivatives exchange β a risk that existed pre-exploit β is now materially more likely given the prominence of the event. Severity: High. Probability of regulatory action within 18 months: ~50β65%.
Solana Ecosystem Contagion β Drift's collapse removes a significant liquidity venue from the Solana ecosystem, reducing overall on-chain activity metrics (fees, volume, active addresses) and potentially weakening the investment thesis for other Solana DeFi protocols that relied on Drift for liquidity routing, JLP yield, or cross-protocol composability. Confidence effects β institutional capital pausing allocation to Solana DeFi broadly β may take 6β12 months to fully manifest. Severity: Medium-High. Probability of measurable TVL contagion across Solana DeFi: ~40β55%.

For funds with exposure to Drift Protocol β either through the DRIFT token, vault deposits, or ecosystem plays β the immediate priority is position assessment and documentation. Vault depositors should monitor the official Drift Protocol communications for any announced compensation mechanism or snapshot dates that may govern future token distributions to affected users. Historical precedent from Euler Finance (2023) and Harmony Horizon Bridge (2022) suggests that recovery processes take 6β18 months even in optimistic scenarios, and partial recovery ratios have ranged from 0% to 100% depending on protocol reserves and attacker negotiations. Funds holding DRIFT tokens should treat the position as effectively impaired β the token's utility is directly tied to protocol TVL and fee generation, both of which have been catastrophically disrupted.
For protocol builders and security teams across Solana DeFi, the Drift exploit represents a definitive case study in operational security failure that demands immediate action. Any protocol holding more than $10 million in TVL governed by a single admin key or low-quorum multisig should treat this as an emergency audit trigger. The minimum acceptable standard in 2026 is a 4-of-7 or higher hardware multisig (Squads Protocol on Solana, Gnosis Safe equivalents elsewhere), with individual key holders geographically distributed, keys stored on hardware security modules (HSMs) or hardware wallets, and no single point of failure in the signing architecture. Time-locked upgrades with a 48β72 hour delay for privileged operations represent an additional layer that would have provided a window to detect and respond to this attack before losses reached $285 million.
For the broader Solana ecosystem and its institutional capital allocators, the Drift exploit demands a structural reassessment of risk frameworks for on-chain derivatives exposure. The "smart contract risk" category that most DeFi risk models assess (audits, formal verification, oracle manipulation resistance) must be explicitly augmented with an "operational security risk" category that scores admin key management quality, upgrade delay mechanisms, team OPSEC practices, and incident response plans. Protocols that achieve demonstrably superior operational security scores β through transparent public multisig setups, time-locks, and bug bounty programs β should command a structural premium in capital allocation decisions. The DeFi ecosystem's long-term institutional adoption depends on demonstrating that $285 million events are preventable through engineering discipline, not just fortune.
30 days: Drift Protocol will release a full post-mortem identifying the specific key compromise mechanism. A governance vote on a recovery/compensation plan will be proposed, likely involving a combination of DRIFT token issuance to affected vault depositors and a multi-year revenue sharing commitment. DRIFT token will remain depressed in the $0.04β$0.06 range absent a dramatic recovery announcement. On-chain investigative firms (ZachXBT, Arkham, Chainalysis) will publish detailed attacker wallet trace reports, and law enforcement referrals will be filed in at least one jurisdiction. Solana DeFi TVL will decline 15β25% ecosystem-wide as confidence effects ripple outward.
180 days: If Drift survives as a protocol, it will have completed a full architectural overhaul β replacing admin key vault governance with a Squads-based multisig, adding on-chain circuit breakers for abnormal withdrawal patterns, and potentially launching a v4 with mandatory time-locked upgrade delays. A $20β50 million ecosystem recovery fund, potentially co-funded by Solana Foundation and strategic backers, may be announced. The legal and regulatory environment will be materially more hostile: at least one regulatory inquiry will be active, and the broader DeFi industry will face accelerating calls for mandatory operational security standards. Competing platforms (Jupiter Perps, Hyperliquid) will have captured a meaningful portion of displaced Drift trading volume.
365 days: The Drift exploit will have become the canonical reference case in DeFi operational security literature, cited alongside the 2016 DAO hack and the 2022 Wormhole bridge exploit as a defining event that reshaped industry practice. Protocols that fail to achieve minimum key management standards will face explicit insurance premium penalties and institutional exclusion lists. The DRIFT token's long-term fate hinges on the recovery ratio achieved for vault depositors β a community that demonstrates fair treatment of harmed users historically rebuilds trust (see Euler Finance's full recovery arc); one that fails to do so faces permanent reputational exile. Solana's DeFi ecosystem will have bifurcated into "institutional-grade" (hardened key management, audited circuits) and "retail-native" tiers, with very different capital profiles for each.
Decrypt β "Solana Drift Protocol Exploited, Upwards of $285 Million Stolen" β https://decrypt.co/363087/solana-drift-protocol-exploited-285-million
DL News β "Solana-based Drift Protocol confirms it's under attack after $285m leaves DeFi platform" β https://www.dlnews.com/articles/defi/drift-protocol-investigating-potential-270-million-hack/
MEXC Learn β "Drift Protocol Hacked for $285M: The Second Largest Exploit in Solana History" β https://www.mexc.com/learn/article/drift-protocol-hacked-for-285m-the-second-largest-exploit-in-solana-history/1
The Block β "'Not an April Fools joke': Major Solana-based trading platform Drift exploited for at least $200 million" β https://www.theblock.co/post/396107/solana-trading-platform-drift-exploited-at-least-200-million
CoinDesk β "Solana DeFi Platform Drift Investigates Suspicious Activity, Tells Users to Halt Deposits" β https://www.coindesk.com/tech/2026/04/01/solana-defi-platform-drift-investigates-suspicious-activity-tells-users-to-halt-deposits
Bloomberg β "Solana-Based DeFi Project Drift Hit by $285 Million Exploit" β https://www.bloomberg.com/news/articles/2026-04-01/solana-based-defi-project-drift-hit-by-285-million-exploit
The Defiant β "Drift Protocol Vault Loses $270 Million in Potential Exploit" β https://thedefiant.io/news/defi/drift-protocol-vault-loses-usd270-million-in-potential-exploit
CryptoTimes β "Drift Protocol Exploited for Over $270M, Token Crashes Over 20%" β https://www.cryptotimes.io/2026/04/02/drift-protocol-exploited-for-over-270m-token-crashes-over-20/
FXStreet β "Solana DEX Drift Protocol suffers $280M+ attack, governance token drops 25%" β https://www.fxstreet.com/cryptocurrencies/news/solana-dex-drift-protocol-suffers-280m-attack-governance-token-drops-25-202604012029
Futunn News β "A $285 million attack, the largest on-chain hack of the year, still stems from the oldest issue: private key vulnerabilities" β https://news.futunn.com/en/post/71006258/a-285-million-attack-the-largest-on-chain-hack-of
GlobalCrypto.tv β "Drift Protocol breach sees $285M drained in one of 2026's largest DeFi exploits" β https://globalcrypto.tv/drift-protocol-breach-sees-285m-drained-in-one-of-2026s-largest-defi-exploits/
AMBCrypto β "Drift Protocol halts operations after suspected $285M exploit as funds move across wallets" β https://ambcrypto.com/drift-protocol-halts-operations-after-suspected-285m-exploit-as-funds-move-across-wallets/
DefiLlama β Drift Protocol TVL & Revenue β https://defillama.com/protocol/drift
CoinGecko β DRIFT Token Price History β https://www.coingecko.com/en/coins/drift-protocol
AInvest β "Drift Protocol Exploit: Biggest DeFi Hack of 2026" β https://www.ainvest.com/news/drift-protocol-sol-exploit-sees-200m-drained-biggest-defi-hack-2026-2604-12/