Drift Protocol·Crypto / Web3·
Crypto assets were stolen.
Decrypt cites Drift’s official notice that it was under active attack and had suspended deposits and withdrawals. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: governance weaknesses
- Consequence
- Reported: Crypto assets were stolen.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Drift Protocol
- Industry
- Crypto / Web3
- Disclosed
- Entry path
- Malware Execution
- Data involved
- Crypto Assets
- Reported impact
- Asset theft · Operational disruption
- Attached evidence
- 8 independent domains · 8 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved malware execution.
ConfidenceSecondaryExact excerpt
E1“a malicious VSCode project that weaponizes the “tasks.json” file to automatically trigger execution of malicious code upon opening the project”
discover.credshields.com · Apr 06 - 02
Reported cause
governance weaknesses
ConfidenceSecondaryExact excerpt
E2“the governance weaknesses that made the attack possible”
discover.credshields.com · Apr 06 - 03
Observed
Crypto assets were stolen.
ConfidenceProbableExact excerpt
E3“Upwards of $285 Million Stolen”
decrypt.co · Apr 01
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The supplied primary source is not included; attack mechanics rely on secondary reporting
- That a Defence review would have prevented this incident
4)Relevance to your product
A single protocol invariant can carry the weight of the complete asset path.
This pattern applies when…
- Products that implement smart-contract, governance, or crypto-asset transfer logic.
Diagnostic questions
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
This incident does not establish your product's risk.
5)Sector context — Crypto / Web3
- 0 incident threads
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 15 incident threads
- 15 incident threads
- 6 incident threads
- 15 incident threads
- 17 incident threads
- 14 incident threads
- 16 incident threads
- 26 incident threads
- Same incident family
- 98 Protocol exploit
- Confirmed share
- 14% 18 confirmed · 108 reported
- Display family
- Vulnerability exploitation Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Crypto / Web3 in Radar →6)Defence control mapping
Context-only control area
Protocol and contract control area
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
- This control is outside the current public external web/API review offer.
7)Public evidence ledger
8 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.
- E1, E2discover.credshields.comDrift Protocol: Incident Post-Mortem - CredshieldsOther public report · Apr 06 · CitedOther public reportCited
Exact excerpt
“the governance weaknesses that made the attack possible”