DEFENCE / RADAR

Public snapshot

Drift Protocol·Crypto / Web3·

Crypto assets were stolen.

Decrypt cites Drift’s official notice that it was under active attack and had suspended deposits and withdrawals. The attached record does not establish the complete downstream scope.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: governance weaknesses
Consequence
Reported: Crypto assets were stolen.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Drift Protocol
Industry
Crypto / Web3
Disclosed
Entry path
Malware Execution
Data involved
Crypto Assets
Reported impact
Asset theft · Operational disruption
Attached evidence
8 independent domains · 8 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved malware execution.

    ConfidenceSecondary
    Exact excerpt

    a malicious VSCode project that weaponizes the “tasks.json” file to automatically trigger execution of malicious code upon opening the project

    discover.credshields.com · Apr 06
    E1
  2. 02

    Reported cause

    governance weaknesses

    ConfidenceSecondary
    Exact excerpt

    the governance weaknesses that made the attack possible

    discover.credshields.com · Apr 06
    E2
  3. 03

    Observed

    Crypto assets were stolen.

    ConfidenceProbable
    Exact excerpt

    Upwards of $285 Million Stolen

    decrypt.co · Apr 01
    E3

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The supplied primary source is not included; attack mechanics rely on secondary reporting
  • That a Defence review would have prevented this incident

4)Relevance to your product

A single protocol invariant can carry the weight of the complete asset path.

This pattern applies when…

  • Products that implement smart-contract, governance, or crypto-asset transfer logic.

Diagnostic questions

  1. Do value and authorization invariants hold across every contract path?
  2. Can one actor manipulate pricing, accounting or bridge state out of sequence?
  3. Are privileged operations bounded under adversarial composition?

This incident does not establish your product's risk.

5)Sector context — Crypto / Web3

126 incident threads in the 365-day public record
  1. 0 incident threads
  2. 1 incident threads
  3. 1 incident threads
  4. 0 incident threads
  5. 15 incident threads
  6. 15 incident threads
  7. 6 incident threads
  8. 15 incident threads
  9. 17 incident threads
  10. 14 incident threads
  11. 16 incident threads
  12. 26 incident threads
Same incident family
98
Protocol exploit
Confirmed share
14%
18 confirmed · 108 reported
Display family
Vulnerability exploitation
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Crypto / Web3 in Radar →

6)Defence control mapping

Context-only control area

Protocol and contract control area

  • Do value and authorization invariants hold across every contract path?
  • Can one actor manipulate pricing, accounting or bridge state out of sequence?
  • Are privileged operations bounded under adversarial composition?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.
  • This control is outside the current public external web/API review offer.

7)Public evidence ledger

8 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E3
    decrypt.coSolana DeFi Exchange Drift Protocol Exploited, Upwards of $285 Million Stolen - DecryptEstablished press · Apr 01 · Cited
    Established pressCited
  2. E1, E2
    discover.credshields.comDrift Protocol: Incident Post-Mortem - CredshieldsOther public report · Apr 06 · Cited
    Other public reportCited
    Exact excerpt
    the governance weaknesses that made the attack possible
  3. S3
    cryptonews.netDrift Protocol suffered an ongoing attack against all its vaults, with over $270M feared stolen within an hourOther public report · Apr 01 · Attached
    Other public reportAttached
  4. S4
    coindesk.comHere is how Drift attackers drained more than $270 million using a Solana feature designed for convenienceEstablished press · Apr 02 · Attached
    Established pressAttached
  5. S5
    elliptic.coDrift Protocol exploited for $286 million in suspected DPRK-linked attack | EllipticSecurity research · Apr 02 · Attached
    Security researchAttached
  6. S6
    securityweek.comNorth Korean Hackers Drain $285 Million From Drift in 10 Seconds - SecurityWeekEstablished press · Apr 03 · Attached
    Established pressAttached
Show all 8 sourcesShow the first six sources
  1. S7
    securityaffairs.comNorth Korea–linked hackers drain $285M from Drift in sophisticated attackSpecialist reporting · Apr 03 · Attached
    Specialist reportingAttached
  2. S8
    theblock.coDrift links $280 million exploit to six-month social engineering op run by suspected North Korean actors | The BlockOther public report · Apr 05 · Attached
    Other public reportAttached
    Exact excerpt
    drained approximately $280 million from the Solana-based perpetuals exchange

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →