Drift outlines a recovery plan for users after $295 million DPRK-linked exploit

Drift outlines a recovery plan for users after $295 million DPRK-linked exploit

Source: CoinDesk

Published:2026-05-05 18:57

BTC Price:$81519.3

#defi #driftprotocol #hack

Analysis

Price Impact

Med

The exploit is significant, but the recovery plan involves tokenized claims and a revenue-backed pool, which could mitigate some of the immediate sell-off pressure. however, the uncertainty around full recovery and the dprk link still pose risks.

Trustworthiness

Med

Price Direction

Neutral

The news is a mixed bag. the exploit is bearish, but the detailed recovery plan is a bullish sign. the neutral stance reflects the balancing act between the negative impact of the hack and the positive outlook of the recovery efforts.

Time Effect

Long

The recovery plan is not immediate. it will take time for the recovery pool to accrue funds, for governance votes to pass, and for the protocol to relaunch. therefore, the impact will be felt over an extended period.

Original Article:

Article Content:

Finance Share Share this article Copy link X icon X (Twitter) LinkedIn Facebook Email Drift outlines a recovery plan for users after $295 million DPRK-linked exploit The lending protocol proposed tokenized claims, a revenue-backed pool and a security overhaul as it works with law enforcement to recover the stolen funds. By Olivier Acuna | Edited by Stephen Alpher May 5, 2026, 6:57 p.m. 2 min read Make preferred on Drift Protocol has announced a recovery plan weeks after suffering a North Korea state-backed exploit of nearly $300 million. (Boitumelo/Unsplash) What to know : Drift Protocol outlined a recovery plan for users hit by its $295 million April 1 exploit, which it attributed to a North Korea–backed DPRK hacking group identified by Mandiant. The plan centers on issuing recovery tokens pegged to verified user losses and funding a pool—starting with about $3.8 million and potentially growing to roughly $151 million from revenue, Tether support and partners—that will accrue until it can fully cover the $295.4 million in losses. Drift, which has frozen some funds and launched a 10% bounty on recovered assets, aims to relaunch in the second quarter as a security-focused exchange with tighter controls, as DeFi platforms including Aave pursue similar industry-wide recovery efforts after major hacks linked to North Korea. Drift Protocol announced Tuesday the implementation of a recovery plan for users affected by a $295 million exploit on April 1, which it attributed to the North Korea state-backed DPRK hacking group identified by forensic firm Mandiant. The attack led the protocol to suspend trading and borrowing immediately after the exploit. Drift said “the majority of stolen assets remain traceable and contained with limited successful off-ramping by the attacker,” with about 130,259 ETH (roughly $31 million) concentrated across four monitored wallets. Drift’s statement explains that the recovery framework centers on issuing a token representing verified user losses. “Each recovery token represents $1 of verified loss,” Drift said, adding that holders would be able to redeem based on the value of a recovery pool funded over time. That pool starts with roughly $3.8 million in remaining protocol assets and is expected to grow through exchange revenue, up to $127.5 million in support from Tether tied to performance, and up to $20 million from partners, Drift said. The pool will accrue until it matches total losses of about $295.4 million, at which point tokens can be redeemed at full value, it added. Drift also said some funds have already been frozen, including about $3.36 million in USDC, while additional assets remain delayed in cross-chain transfers. Legal efforts to seize and reissue funds are ongoing, it said. The protocol also launched a public bounty offering 10% of recovered assets. Drift plans to relaunch in the second quarter as a “security-first” exchange with changes including new multisig controls, time-locked operations, key rotation and reduced product scope focused on perpetuals trading. “The Drift team is taking considered measures to ensure that users are made whole,” the team said, adding that final decisions will be subject to governance votes. Drift’s recovery plan announcement comes a week after Aave said it was spearheading a coordinated DeFi recovery effort to rescue Kelp DAO, the second largest DeFi exploit this year, which was also carried out by North Korean-backed hackers. The so-called Lazarus group drained nearly $280 million. In this case, Aave has been able to garner span donations, deposits, and credit lines from across the crypto space. Hack More For You Tokenization won't disrupt banking rails but improve them, Wall Street executives say By Krisztian Sandor , AI Boost | Edited by Stephen Alpher 2 minutes ago Executives from Citigroup, JPMorgan and DTCC said at Consensus that genuine client demand is driving real-world use of tokenized assets. What to know : Major Wall Street institutions, including Citigroup, JPMorgan and DTCC, say blockchain-based tokenization is quietly moving into production, handling real volumes for real clients rather than remaining a pilot technology. Banks are integrating blockchain rails into existing market infrastructure to enable 24/7, real-time movement of money and securities, reshaping corporate treasury,... Read full story Latest Crypto News Tokenization won't disrupt banking rails but improve them, Wall Street executives say 2 minutes ago Bitcoin extends gains to $81,500 as tokenization push lifts Bullish, Galaxy, Centrifuge 6 minutes ago Rep. Steven Horsford pitches PARITY Act as 'durable floor' for crypto tax at Consensus Miami 1 hour ago Solana’s 'Alpenglow' upgrade could arrive next quarter, co-founder Yakovenko says 1 hour ago Western Union’s Solana-based stablecoin could reshape its payment model, analyst says 1 hour ago Figure targets Fannie Mae and Freddie Mac in mortgage push, citing massive cost cuts for borrowers 1 hour ago Top Stories Ripple CEO Brad Garlinghouse says Clarity better than chaos as Senate hits key moment 2 hours ago Consensus Miami Day 1: Real-time coverage and highlights from on the ground 5 hours ago Crypto's value is from being outside regulatory apparatus, says Arthur Hayes 3 hours ago Coinbase cuts 14% of staff as AI reshapes how crypto companies operate 7 hours ago Crypto.com’s high-rolling head of marketing to leave after almost six years 5 hours ago Crypto platform Bullish to buy Equiniti for $4.2 billion, building tokenized securities infrastructure 8 hours ago