
According to reports from AMBCrypto, Drift Protocol has outlined a structured recovery plan following its $295 million exploit. The protocol confirmed that the 1 April attack was linked to a DPRK-affiliated threat actor, with forensic firm Mandiant involved in the investigation. As reported by AMBCrypto, approximately 130,259 ETH, worth around $293 million, remains concentrated across four attacker-controlled wallets, with law enforcement efforts ongoing though no confirmed recovery timeline has been provided. The attack affected user balances that were snapshotted at 18:31:47 UTC on April 1, with oracle prices taken from 16:06:00 UTC before the attack distorted markets.
To compensate users, Drift plans to issue a 'recovery token' that represents $1 of verified loss. According to AMBCrypto, these tokens will act as claims on a recovery pool funded through multiple sources, including protocol revenue, up to $127.5 million in support from Tether, and additional partner capital of up to $20 million. The recovery pool will continue to grow until it matches total losses of approximately $295 million. As per the protocol's announcement, all affected users will receive transferable recovery tokens based on SPL standard, with each token representing $1 of proven loss that has been independently verified. Users can redeem tokens once the pool reaches a $5 million minimum threshold, with payouts calculated using a formula that considers both the total recovery pool value and outstanding token supply. The tokens are burn-on-redeem and one-time only, meaning users who cash out before the pool reaches the full $295.4 million forfeit any further claim, with unclaimed tokens burned to lift redemption values for remaining holders.
As reported by AMBCrypto, Drift is targeting a relaunch in Q2 2026, with a redesigned architecture focused on security. The key changes include new program deployment with rotated keys, removal of high-risk product features, implementation of multisig controls with timelocks, and mandatory audits before redeployment. The platform will also shift to a more streamlined model, focusing primarily on perpetual trading. According to the protocol's announcement, the relaunch will include deploying an entirely new program, generating new wallet addresses and rotating cryptographic keys to make the system more secure. A significant overhaul of the multisig governance structure will take place to open it up to more community involvement in a direction towards decentralized governance, with elimination of durable nonces, halting earn products and implementation of a full operational security audit. When Drift comes back online, it will be a leaner, perps-only venue settled in USDT rather than USDC, removing the durable-nonce attack surface central to the April 1 breach.
Despite the comprehensive recovery plan, user sentiment remains largely negative, with affected participants taking to social media to voice anger that the proposal does not offer enough immediate assistance. As reported by AMBCrypto, detractors argue that recovery tokens postpone payouts and shift risk back to victims, who are left hanging with little hope of payment. One user commented publicly: "In other words, victims get nothing. And the Drift team that caused this takes no real loss. You are wrong if you think you can walk away from this easily." The protocol acknowledges this trade-off, noting that users must weigh pressing liquidity needs against the expectation of greater returns as the recovery pool grows. DriftProtocol used approximately $3.8 million in residual protocol funds from distribution to start the general recovery process, with assets swapped for USDT to ensure stability for initial redemptions. The roughly $20 million insurance fund, which was untouched, will be subject to a separate DAO vote on whether it pays out to depositors or rolls into the recovery pool.