No connection

Search Results

Crypto Score 75 Neutral

Drift Protocol Sends Onchain Messages to Wallets Tied to $280M Exploit

Apr 03, 2026 10:26 UTC
BTC-USD, ETH-USD, ^VIX
Immediate term

Drift Protocol has initiated onchain communication with wallets linked to a $280 million exploit, while an unknown sender attempts to pressure the attacker. The move underscores ongoing efforts to recover stolen funds and could influence market sentiment.

  • Drift Protocol has sent onchain messages to four wallets tied to a $280 million exploit.
  • An unknown sender using the ENS name readnow.eth demanded 1,000 ETH in exchange for withholding information about the attacker.
  • The exploit has affected at least 20 Solana protocols, including Gauntlet, which faced estimated losses of $6.4 million.
  • Cyvers described the attack as a 'weeks-long, staged operation' involving durable nonces on Solana.
  • The attack has drawn comparisons to the Bybit hack, with both involving signers unknowingly approving malicious transactions.
  • Industry observers speculate North Korea-linked actors may be involved, though details remain unconfirmed.

Drift Protocol, a decentralized exchange (DEX) on the Solana blockchain, has begun onchain outreach to wallets associated with a $280 million exploit. The protocol, which operates on the Solana network, announced on X that it had sent messages from its Ethereum address (0x0934faC) to four wallets believed to hold stolen Ether (ETH). The messages, delivered via onchain channels, aim to establish communication with the attacker and encourage dialogue through Blockscan chat. “We are ready to speak,” Drift stated, highlighting the use of onchain messaging as a standard practice in responding to exploits. This tactic allows protocols to engage with attackers while maintaining anonymity. Similar approaches in past incidents, such as the Euler Finance hack, have occasionally led to partial fund recoveries. The outreach by Drift followed a separate onchain message from an unidentified sender using the ENS name readnow.eth. This sender claimed to possess knowledge of the attacker’s identity and demanded 1,000 ETH in exchange for withholding information. However, the authenticity of these claims remains unverified, and the message could be an attempt to mislead or pressure the wallet holder. The incident illustrates how unverified communications can proliferate onchain in the aftermath of crypto exploits, alongside official efforts. According to SolanaFloor, the exploit has impacted at least 20 Solana protocols, including the DeFi platform Gauntlet, which reportedly faced losses of approximately $6.4 million. Blockchain security firm Cyvers noted that the attack’s impact continued to unfold as of Friday morning, with no funds recovered 48 hours after the breach. Cyvers described the attack as a “weeks-long, staged operation,” citing the use of durable nonces—a Solana feature enabling pre-signed transactions for future execution—as evidence of premeditation. The attack’s methodology has drawn comparisons to the Bybit hack, with Cyvers observing that both incidents involved signers unknowingly approving malicious transactions, albeit through different techniques. Some industry experts, including Ledger’s chief technology officer Charles Guillemet, have speculated that the exploit may involve actors linked to North Korea, though these claims remain unconfirmed. The ongoing situation highlights the challenges of securing decentralized systems and the potential for coordinated, sophisticated attacks to destabilize multiple protocols simultaneously.

Sign up free to read the full analysis

Create a free account to unlock full AI-curated market articles, personalized alerts, and more.

Share this article

Related Articles

Stay Ahead of the Markets

Join thousands of traders using AI-powered market intelligence. Get personalized insights, real-time alerts, and advanced analysis tools.

Home
Terminal
AI
Markets
Profile