Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

Drift Protocol Hack: $270M Exploit as Attacker Bridges Funds to Ethereum and Buys ETH

Over $270M drained from Drift Protocol vaults as attacker swaps assets, bridges funds, and accumulates ETH across multiple wallets.

by Saravana Kumar Mahendran
April 2, 2026 - Updated on April 3, 2026
in Security & Hacks
0 0
Drift Protocol exploit drains $270M in crypto assets

Over $270M drained from Drift Protocol as attacker shifts funds into ETH

Share on FacebookShare on Twitter

The ongoing exploit of Solana-based perpetuals DEX Drift Protocol has seen over $270 million in assets drained, with the attacker actively converting stolen funds into ETH after bridging to Ethereum, according to on-chain tracking by Lookonchain.

The incident, first flagged earlier today, involves suspicious transfers to the wallet HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES. Initial reports confirmed roughly $270 million in various assets including JLP, USDC, cbBTC, and other tokens were moved out of Drift’s vaults, which reportedly dropped from approximately $309 million to as low as $24 million in value.

Latest On-Chain Developments

  • Swapping and Bridging Activity: The exploiter has been rapidly swapping stolen assets into USDC and bridging them to Ethereum to purchase ETH. As of 17:49 UTC, 19,913 ETH (valued at ~$42.6 million) had been acquired via the Ethereum address 0xd91a122b585bc588c9a48d0995ee0d7b4f8ab7dd.
  • Update at 18:17 UTC: The attacker’s ETH purchases have now reached 38,820 ETH (approximately $82.66 million).
  • Additional Routes: Additional Routes: The exploiter bridged SOL to Ethereum via Chainflip (from address 6W6Lfe, Swap ID: 1436734) to the destination address 0xd91a122b585bc588c9a48d0995ee0d7b4f8ab7dd. It did not go to HyperLiquid or Binance.

This conversion activity is ongoing, with the attacker appearing to favor ETH as the primary exit asset. No signs of freezing or intervention on the USDC side have been publicly confirmed yet.

Official Response from Drift Protocol

Drift Protocol 270 Million USD Hack
Drift Protocol 270 Million USD Hack X Post

“We are observing unusual activity on the protocol. We are currently investigating. Please do not deposit funds into the protocol while we investigate. This is not an April Fools joke. Proceed with caution until further notice. We’ll provide additional updates from this account.”

As of 18:54 UTC, no additional statements have been issued by @DriftProtocol. The protocol remains in a high-risk state.

Broader Context and Market Impact

  • Scale: The breach represents roughly 50% of Drift’s TVL at the time and is the largest reported Solana ecosystem exploit since the 2022 Wormhole incident. It also ranks as one of the biggest DeFi hacks of 2026 so far.
  • Phantom Wallet Advisory: Wallet provider Phantom has issued a warning for users attempting to access Drift, noting security team investigations and requiring acknowledgment of risks before proceeding.
  • DRIFT Token: The governance token continued to trade under heavy pressure following the news.

What Users Should Do

  • Avoid Interaction: Do not deposit, trade, or interact with Drift Protocol until the team confirms the situation is resolved.
  • Wallet Safety: Revoke any approvals tied to Drift contracts immediately. Monitor connected wallets closely.
  • Official Sources Only: Rely exclusively on @DriftProtocol for verified updates. Ignore unsolicited links, refund offers, or compensation claims; these are phishing vectors.
  • Track Activity: Follow on-chain explorers (Arkham Intelligence, Solscan) and accounts like @lookonchain for real-time movements of the flagged wallets.

The exploit remains live and fluid, with the attacker still liquidating positions and repositioning into ETH. This event highlights persistent risks in DeFi smart contracts and multi-chain bridging. Further updates from Drift or security firms are expected as the investigation progresses.

This independent report compiles official statements and verified on-chain data as of April 1, 2026, 18:54 UTC. Figures are preliminary and subject to change.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto HacksEthereumSolana

Related Posts

THORChain Exploited
Security & Hacks

THORChain Exploited for Over $10 Million in Crypto Assets Across Multiple Chains

by Saravana Kumar Mahendran
May 15, 2026

Decentralized cross-chain liquidity protocol THORChain has suffered a significant exploit, with losses estimated at over $10 million. Blockchain security firm...

Read moreDetails
JPMorgan Says Ethereum and Altcoins Still Lag Behind Bitcoin

JPMorgan Says Ethereum and Altcoins Still Lag Behind Bitcoin

May 15, 2026
Transit Finance Hacked Again

Transit Finance Hacked Again: Cross-Chain DeFi Protocol Loses $1.88 Million in Latest Exploit

May 13, 2026 - Updated on May 14, 2026
Mistral AI Supply Chain Attack

Mistral AI Supply Chain Attack: Hackers Inject Malware Into PyPI Package, Microsoft Warns Developers

May 13, 2026
Ethereum Launches Clear Signing Standard to Prevent Blind Signing Scams

Ethereum Launches Clear Signing Standard to Prevent Blind Signing Scams

May 13, 2026
Roaring Kitty X Account Hacked

Roaring Kitty X Account Hacked: Solana Memecoin $RKC Pumps to $12M Before Crash

May 12, 2026
INK Finance Suffers $140K

INK Finance Suffers $140K Drain on Polygon: Attacker Exploits Treasury Proxy via Whitelist Flaw and Flash Loan

May 11, 2026
Next Post
Paradigm Explores Prediction Market Trading Terminal Development

Paradigm Explores Prediction Market Trading Terminal Development

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Bhutan BTC Holdings Drop From 13,000 Bitcoin to 3,100
  • THORChain Exploited for Over $10 Million in Crypto Assets Across Multiple Chains
  • Michael Saylor’s Strategy Repurchases $1.5 Billion of 2029 Convertible Notes

Categories

  • AI × Crypto
  • Data & Dashboards
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.