
Drift Protocol announced Tuesday the implementation of a comprehensive recovery plan for users affected by a $295 million exploit on April 1, which it attributed to the North Korea state-backed DPRK hacking group identified by forensic firm Mandiant. According to reports from Drift Protocol, the attack led the protocol to suspend trading and borrowing immediately after the exploit. The recovery framework centers on issuing a token representing verified user losses, with each recovery token representing $1 of verified loss that holders can redeem based on the value of a recovery pool funded over time. The update, published on 5 May, confirms that the 1 April attack was linked to a DPRK-affiliated threat actor, with forensic firm Mandiant involved in the investigation.
The recovery pool starts with roughly $3.8 million in remaining protocol assets and is expected to grow through multiple funding sources. As reported by Drift Protocol, the pool will grow through exchange revenue, up to $127.5 million in support from Tether tied to performance, and up to $20 million from partners. The pool will accrue until it matches total losses of about $295.4 million, at which point tokens can be redeemed at full value. Drift has already frozen some funds, including about $3.36 million in USDC, while additional assets remain delayed in cross-chain transfers. According to the protocol, approximately 130,259 ETH, worth around $293 million, remains concentrated across four attacker-controlled wallets, with law enforcement efforts ongoing though no confirmed recovery timeline has been provided.
Drift plans to relaunch in the second quarter as a 'security-first' exchange with enhanced controls including new multisig controls, time-locked operations, key rotation and reduced product scope focused on perpetuals trading. According to Drift Protocol, the protocol also launched a public bounty offering 10% of recovered assets. The team stated that final decisions will be subject to governance votes, with the Drift team taking considered measures to ensure that users are made whole. Unlike immediate reimbursement models, Drift's approach spreads recovery over time through revenue and external funding, with repayments not interfering with trading liquidity once the platform relaunches.
Drift's recovery plan announcement comes a week after Aave said it was spearheading a coordinated DeFi recovery effort to rescue Kelp DAO, the second largest DeFi exploit this year, which was also carried out by North Korean-backed hackers. As reported by Drift Protocol, the so-called Lazarus group drained nearly $280 million in that case. In this case, Aave has been able to garner span donations, deposits, and credit lines from across the crypto space, demonstrating broader industry coordination efforts following major DeFi hacks linked to North Korea. The structure means users may need to wait for full recovery depending on fund inflows and enforcement outcomes.