Drift Trade

Orange · 55/100

Executive summary

Drift Trade is a Solana-native decentralized perpetual futures and margin trading protocol that scored 49/100 (orange band), reflecting severe operational and security failures despite a history of professional audits. The protocol suffered a catastrophic $285–295 million exploit on April 1, 2026, through social-engineering compromise of its Security Council multisig, enabling attackers to manipulate oracles, inject fake collateral, and drain user funds; remediation remains incomplete as of September 2026.

  • Security: Multiple audits by Trail of Bits (2022–2023), Neodyme (2024), Zellic (2022), and OtterSec (2023) covered core Solana programs and auxiliary components; Neodyme's 2024 audit flagged 1 critical issue (cranker-fee accounting theft vector) and noted that admin instructions lacked oracle validation—a gap exploited in the April 2026 incident. Post-incident, Drift announced planned audits by OtterSec and Asymmetric Research for a full protocol reboot, but no finalized public reports are available.
  • Incidents: Two major events: a May 2022 market-manipulation incident ($14.5M loss, fully returned) and the April 2026 privileged-key compromise ($285–295M stolen, attributed to North Korean-linked UNC6862 group). The 2026 exploit leveraged pre-signed durable-nonce transactions, compromised multisig signers, and fake collateral; no user funds have been recovered, and the protocol remains paused with remediation in progress.
  • Governance & custody: Non-custodial architecture with user assets held in on-chain vaults; governance split between Realms DAO, a Security Council (historically 2-of-5 multisig with upgrade/admin powers), and a Futarchy DAO. The April 2026 breach demonstrated that the Security Council could drain user funds without fresh token-holder votes; proposed fixes include new community multisig, timelocks, dedicated signing devices, and disabled durable nonces, but deployment is unverified.
  • Top risks: (1) Administrative key compromise remains the dominant risk; proposed post-incident controls are unverified as live. (2) Oracle/collateral manipulation: the exploit involved fake assets treated as valid collateral, exposing severe listing and oracle-validation gaps. (3) Counterparty/dependency risk: reliance on Pyth/Switchboard oracles, USDC/USDT stablecoin issuers, and Solana network uptime. (4) Unresolved liabilities: ~$295M in outstanding user losses with no confirmed recovery plan or timeline.
  • Strengths: Fast Solana execution, capital-efficient cross-margining, deep liquidity via hybrid AMM/auction/orderbook model, non-custodial on-chain transparency, and robust pre-incident risk-engine design; active bug bounty (Immunefi, up to $500k) and historically strong audit coverage of core programs.
  • Unverified: Current TVL, live contract state, deployed bytecode match to audited commits, exact Security Council signer set and timelock parameters, Insurance Fund size and coverage ratio, DFX recovery-token claim process, and whether the proposed relaunch controls (new multisig, timelocks, audits) are operationally deployed; all marked Not verifiable as of September 2026.
  • Recommended exposure: Zero new exposure until independent verification confirms: (a) completion and public release of OtterSec/Asymmetric relaunch audits, (b) on-chain deployment of timelocked multisig with disclosed signers and emergency procedures, (c) user-fund recovery plan with transparent liability accounting, and (d) at least 90 days of incident-free operation post-relaunch with published reserves and collateral composition. Existing positions should be exited or hedged given unresolved $295M liability and unverified remediation status.
  • Open questions: (1) What is the current on-chain TVL, collateral mix, and vault balance? (2) Have the OtterSec and Asymmetric relaunch audits been completed and published? (3) What is the exact multisig configuration, timelock delay, and signer identity for the new community multisig? (4) What is the Insurance Fund balance and coverage ratio relative to outstanding liabilities? (5) What is the timeline and mechanism for user reimbursement or DFX recovery-token claims? (6) Has the upgrade authority been renounced or placed under verifiable timelock control? (7) What is the current governance token distribution and voting participation rate?

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 8 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-04-16)
Incidents 20% 0 0.0 1 open incident(s), $295,706,375 at risk = 46017.1% of TVL (threshold 10%); penalty proportional to assets at risk
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $642,602 = 0% of reference ($17,538,184,136)
Data confidence 91 7/7 critical categories; 22/40 verified facts; 40/40 fresh (180d)

Identification

protocol identification

two sources

Drift Trade (often Drift Protocol) is a Solana-native decentralized trading protocol focused on perpetual futures, spot, margin, and lending. It is not verifiable on-chain via Dune as of 2026-09-04. Identification & basic metadata

  • Name: Drift Protocol / Drift Trade
  • App / website: app.drift.trade (trading UI), marketing site drift.trade.
  • Docs: Hosted under docs.drift.trade, including a dedicated Security → Audits section.
  • Category: Solana DeFi perpetual futures & multi-market DEX with spot, borrowing/lending, unified margin.
  • Launch date: Multiple independent sources state Drift launched in 2021 as an early Solana DeFi project.
  • Chains: Solana only; all descriptions emphasize it is built *natively on Solana*.
  • Native token: DRIFT governance token, used for governance and rewards. Main contracts / program addresses (Solana)
  • External technical write-up identifies the mainnet program address as dRiftyHA39MWEi3m9aunc5MzRF1JYuBsbn6VPcn33UH and a vault address JCNCMFXo5M5qwUPg2Utu1u6YWp3MbygxqBsBeXXJfrw.
  • This article attributes these addresses to the production Drift deployment and describes them as the orderbook program and vault used for cross-margining and liquidity.
  • Explorer-level verification status (e.g., whether the program is marked as “verified” on Solana explorers) is Not verifiable as of 2026-09-04 within the current constraints. Audits & security
  • Drift maintains an audits page listing formal security audits; the most recent note says no high‑severity findings impacting confidentiality, integrity, or availability were uncovered.
  • Specific firms and scopes are not fully visible from the snippet but indicate multiple audits over different versions. Fork lineage / originality
  • Independent deep-dive sources describe Drift as Solana-native, architecting its own hybrid liquidity stack (orderbook + just‑in‑time auction + AMM) and Swift Protocol layer, not as a fork of an Ethereum perpetuals DEX.
  • There is no evidence in independent coverage that Drift is a direct fork of another protocol; it is portrayed as an original Solana implementation.
  • A 2022 “risk event” is referenced, after which Drift v2 was rebuilt, but this is an internal redesign rather than a fork of a different upstream codebase.
  • No records of malicious-modification history in related forks of Drift were found; this is Not verifiable as of 2026-09-04 beyond available media and docs. Contradiction callout
  • On-chain verification via raw data is not accessible in this run; any TVL, volume, or holder metrics from aggregators cannot be cross‑checked against chain state and are therefore not on-chain verified and Not verifiable as of 2026-09-04.
Evidence (13)

maturity

two sources

Drift Trade appears to be a live product portal, not just a landing page: the main site advertises trading functionality (“Trade Perpetual Futures”), and the docs point users to app.drift.trade for account pages and onboarding, which implies an operational app rather than a static marketing site. The documentation stack is mature, with a dedicated API page, SDK/docs references, a Data API playground, and a self-hosted HTTP gateway for programmatic interaction. On open API support, the evidence is strong: Drift documents a public Data API and websocket streams, plus a self-hosted gateway and SDKs for developers.

That is sufficient to conclude it has an open developer API surface. What cannot be verified here is live deposit/withdrawal status, broken-link prevalence, or whether specific metrics are fake/template placeholders; those require direct app inspection and chain-level checks that are not available in this run. Not verifiable as of 2026-09-04.

Evidence (6)

Security

bug bounty

two sources

Drift Trade has an active bug bounty program run through Immunefi, focused on smart-contract vulnerabilities; UI/client-only bugs are out of scope. It appears to have started on 2022-02-15. The current parameters are: Critical bugs pay 10% of the exploit value up to $500,000; High bugs are $10,000 to $50,000 case-by-case; Medium/Low bugs are $1,000 to $5,000 case-by-case.

Submissions require a detailed report, and for critical/moderate bugs a proof of concept on a privately deployed mainnet contract; payouts are in USDC and handled by Drift. I found no independently verifiable postmortem or public results summary in the retrieved sources, so results are not verifiable as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$500K
Since
2022-02-15
Evidence (3)

counterparty risks

two sources

Assessment date: September 6, 2026. Chain: Solana. dependency_failure_active: true — Drift experienced a material operational/security failure on April 1, 2026. The protocol was paused, and the latest official update located (June 4, 2026) described a full reboot and relaunch rather than normal operations.

A currently live, fully restored deployment is Not verifiable as of September 6, 2026. max_exposure_pct: null — on-chain exposure percentages are Not verifiable as of September 6, 2026 because Dune MCP was unavailable. DeFiLlama reports approximately $286.7m TVL, but this is an analytics estimate, not raw on-chain verification. ### Key dependencies and counterparty risks

  • Oracles/manipulation: Drift depends on Pyth as the primary oracle source and Switchboard as an alternative. Guardrails, confidence checks and TWAP mechanisms reduce—but do not eliminate—stale-price, thin-liquidity, feed-outage and manipulated-collateral risk. The April incident reportedly involved a fabricated asset being treated as valid collateral, demonstrating severe oracle/listing/administrative dependency risk.
  • Stablecoins: Historically USDC was the settlement/quote asset; Drift’s proposed relaunch migrates settlement to USDT. This concentrates issuer, freeze, depeg, sanctions and redemption risk in Circle/Tether, respectively. Tether also proposed up to $127.5m of recovery support and a market-making facility, creating direct counterparty dependence.
  • LSTs and collateral: Supported or previously held collateral includes mSOL, JitoSOL, bSOL, dSOL and other SOL derivatives, plus SOL and volatile tokens. Failure, depeg, validator/slashing, liquidity or smart-contract risk at an LST issuer can create correlated liquidation and bad-debt losses.
  • Custody/admin: User assets are marketed as non-custodial, but protocol-admin multisig/signing infrastructure was a critical dependency; the April exploit reportedly used social engineering and durable nonces to obtain malicious approvals.
  • Bridges/CEX/MMs/RWA: No routine bridge, RWA issuer/SPV or centralized custodian dependency was verified. Post-incident fund movement involved bridges/exchanges, while the relaunch plan depends on designated market makers. Not verifiable as of September 6, 2026 for exact exposures or current counterparties.
Dependency failure active
Yes
Evidence (5)

crypto custody

unverified

Drift Trade is organized as a non-custodial, self-custody protocol on Solana: users keep control of their crypto in their own wallet, while Drift’s smart contracts manage deposits, positions, orders, and settlement on-chain. The protocol documentation says user trading state lives in per-user on-chain accounts, and that all token deposits are held in a global collateral vault, with the insurance fund vault as the only stated exception. So custody is not held by a centralized intermediary; instead, user assets are deposited into protocol-controlled on-chain vaults/accounts for trading and borrow-lend functions.

Segregated assets
No
Evidence (3)

incident

one source

Drift Trade: Market Manipulation via Risk Parameter Abuse on Solana; loss $14,500,000, returned $14,500,000 (DeFiLlama hacks registry). Remediation status: resolved (retained evidence).

Date
2022-05-11
Cause
Other
Loss
$14.5M
Status
resolved
Recovered
$14.5M
Reimbursed
Yes
Classification
Market Manipulation
Technique
Risk Parameter Abuse
Event id
drift-2022-05-11-pnl-accounting-shortfall
Evidence (3)

incident

two sources

On April 1, 2026, privileged-key/social-engineering compromise enabled administrative takeover using pre-signed durable-nonce transactions. The attacker added fake CVT collateral, altered oracle/risk parameters, and drained user assets from Drift spot, borrowing/lending, vault and trading products. Drift’s incident accounting lists $295,706,374.93 stolen across at least 18 asset types; independent analysis estimates attacker proceeds at approximately $285 million.

Drift froze deposits and withdrawals, removed compromised signers, engaged law enforcement, Mandiant and forensic firms, and attributed the operation to the North Korean-linked UNC6862 group. Planned and reported fixes include a protocol reboot, fresh program/address, new community multisig, dedicated signing devices, independent transaction verification, timelocks, real-time alerts, disabling durable nonces, independent audits, and migration from USDC to USDT. Insurance Fund depositors became eligible to withdraw from July 7, 2026, but the DFX recovery-token claim window remains unannounced; no confirmed recovery of the stolen assets or full reimbursement of exploit-affected users was identified as of September 6, 2026.

Current status: remediation_in_progress.

Date
2026-04-01
Cause
Key compromise
Loss
$295.7M
Attacker proceeds
$285.0M
Status
remediation in progress
Recovered
$0
Reimbursed
No
Event id
drift-2026-04-01-privileged-access-takeover
Evidence (5)

incident

one source

Drift Trade: Access Control via Proxy Upgrade Hijack on Solana; loss $295,000,000 (DeFiLlama hacks registry).

Date
2026-04-01
Cause
Smart-contract exploit
Loss
$295.0M
Status
status unknown
Classification
Access Control
Technique
Proxy Upgrade Hijack
Evidence (1)

key management

two sources

Drift’s key management is organized in two layers. For user access, Drift supports passwordless email login: a user receives a code by email, and the first successful login creates a non-custodial Magic Wallet with its own unique address and private key that can be retrieved again via email authentication; Drift says neither Drift nor Magic Link has access to the user’s wallet or private keys. For protocol/admin control, Drift’s governance is split into a multi-branch DAO, including a Security Council that governs upgrades and can approve changes to fees, leverage, and market/risk parameters; the protocol architecture also centers on a global State account that holds admin keys and protocol-wide configuration.

Evidence (4)

smart-contract

two sources

As of September 6, 2026. Drift Trade is a Solana program, not an EVM proxy system. The identified Drift v2 program is dRiftyHA39MWEi3m9aunc5MzRF1JYuBsbn6VPcn33UH; an explorer snapshot labels it executable, upgradeable, and controlled by upgrade authority GA5aPX7hFNaxoi8akdbcFVMCrkdfbYC42q7BERPguTNo. The snapshot is approximately three months old, so current authority custody/type is not confirmed. Architecture ``text User wallet │ deposits / trades / withdrawals ▼ Drift v2 Solana program ├─ user/margin + market state PDAs ├─ oracle integrations / crank permissions ├─ admin-controlled risk, fee, market and pause parameters └─ BPF Upgradeable Loader ──> upgrade authority └─ can replace program logic `` Admin and control risk. There is no EVM proxy-admin contract; the analogous root role is the Solana BPF Loader upgrade authority.

A compromised upgrade authority can deploy arbitrary logic, potentially bypassing normal withdrawal, oracle, fee, liquidation and pause checks, and therefore represents a protocol-wide drain/freeze risk. Solana programs can become immutable only when upgrade authority is set to None; that status is not currently verified here. Public governance materials historically describe a Security Council with authority over risk parameters, fees, market listings and program upgrades, but current signer set, multisig threshold, timelock delay, emergency guardian, renounced roles, and exact instruction-level permissions are Not verifiable as of September 6, 2026.

Dune was unavailable; therefore proxy-admin event analysis, on-chain timelock measurement, current admin balances, and user-exit testing are also Not verifiable as of September 6, 2026. Bottom line: upgradeability and catastrophic key-compromise exposure remain material. Users may be unable to exit if withdrawals are paused or malicious code is deployed. Treat the deployment as non-immutable until current loader state, authority custody, multisig threshold, timelock, and audited-build matching are independently rechecked.

Admin can drain
Yes
Upgradeable
Yes
Evidence (4)

audit

one source

OtterSec’s published report covers Drift’s auxiliary snap-solana MetaMask Snap, not the core Solana trading program.

Auditor
OtterSec
Report date
2023
Scope
snap-solana integration assessed August 2–4, 2023 against commit 04fa431; transaction display, wallet interaction, RPC handling, and user-safety behavior.
Findings
0 Critical, 0 High, 0 Medium, 0 Low; 3 Informational suggestions concerning transaction-detail display, unpinned NPM dependencies, and RPC type-confusion risk.
Fix status
The report records remediation for dependency and RPC-type suggestions in commit 50a9081. Match to the currently deployed Snap is Not verifiable as of September 6, 2026; not applicable to core-program bytecode.
Report url
https://uploads-ssl.webflow.com/6310e7dee49f0866da8eed4c/6500a96167c4910943572126_drift_snap_audit_final%20%281%29.pdf
Report id
doc:0a044d925a6c944a
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

unverified

Trail of Bits published its Drift security-audit update on March 13, 2023, covering the November–December 2022 audit and January 2023 remediation review.

Auditor
Trail of Bits
Report date
2023-03-13
Scope
Drift decentralized exchange and on-chain program; source-code review conducted November 7–December 2, 2022, with fix review January 23–25, 2023.
Findings
No high-severity flaws affecting confidentiality, integrity, or availability were reported. Exact Critical/Medium totals are Not verifiable as of September 6, 2026. The official update notes unresolved or partially resolved findings and one undetermined finding concerning testing code used in production.
Fix status
Fixes and mitigations were reviewed by Trail of Bits, but outstanding/undetermined items remained at close. Current deployed-program bytecode match: Not verifiable as of September 6, 2026.
Report url
https://www.drift.trade/updates/tob-security-audit
Report id
doc:3a2b444dd7f3ec19
Evidence (1)

audit

two sources

The Zellic report date is confirmed as February 16, 2022; the previously recorded date was not erroneous.

Auditor
Zellic
Report date
2022-02-16
Scope
Drift Protocol Solana program; early deployment/codebase review. Exact reviewed commits and component boundaries are not verifiable from accessible report extraction.
Findings
Critical, High, and Medium finding counts: Not verifiable as of September 6, 2026. The report is publicly listed by Zellic, but accessible web extraction does not expose its findings table.
Fix status
Remediation status: Not verifiable as of September 6, 2026. Current deployed-program bytecode match: Not verifiable as of September 6, 2026.
Report url
https://github.com/Zellic/publications/blob/master/Drift%20Protocol%20Audit%20Report.pdf
Report id
doc:d70e59ec8de52c48
Evidence (2)

audit

one source

Corrected publication metadata: Neodyme’s auditor index dates the Drift Protocol report to June 27, 2024 (the PDF describes work conducted February–early April 2024), rather than May 10, 2024.

Auditor
Neodyme AG
Report date
2024-06-27
Scope
Drift protocol-v2 Solana on-chain program; implementation security, architecture, business logic, economic attacks, and authority structure. Reviewed commits 58ddf999… through 0ee9e960…; some changes were only partially reviewed.
Findings
1 Critical, 0 High, 2 Medium, 4 Low, 3 Informational. The Critical finding concerned cranker-fee accounting that could enable gradual theft; Medium findings affected margin and pause/deposit/withdraw restrictions.
Fix status
Most findings were resolved and fixes were verified by Neodyme, but the report records acknowledged or pending items. Current deployed-program bytecode match: Not verifiable as of September 6, 2026.
Report url
https://neodyme.io/reports/Drift.pdf
Report id
doc:d9f11e94cda5fc28
Evidence (2)

audit

two sources

Neodyme AG audited Drift’s protocol-v2 Solana program in early 2024, performing a detailed security analysis of version 2 of the on-chain protocol. The audit covered the core v2 program, including admin instructions such as InitializeSpotMarket and oracle handling.

Auditor
Neodyme AG
Report date
2024-04-10
Scope
Drift protocol v2 Solana program (on-chain perpetuals / spot markets), focusing on smart-contract logic, oracle usage, and admin instructions; static analysis and targeted testing at specific git commit(s).[2][12]
Findings
The Neodyme report lists: **1 critical**, 0 high, **2 medium**, 4 low, and 3 informational issues.[2] Independent commentary highlights that the audit flagged a now‑material issue: admin instructions accepted oracle accounts with zero validation, contributing to the 2026 exploit path.[12]
Fix status
Drift’s materials and the Neodyme report indicate issues were acknowledged and fixes proposed; Neodyme’s document usually includes verified/unverified remediation notes.[2] However, on-chain confirmation of which findings are fully remediated in current deployed Solana programs is Not verifiable as of 2026-09-04. The later exploit suggests at least one oracle‑validation issue remained exploitable operationally despite being flagged.[12] Bytecode‑match to live contracts: Not verifiable as of 2026-09-04.
Evidence (3)

audit

one source

Neodyme — Security Audit – Drift Protocol

Auditor
Neodyme AG
Report date
2024-05-10
Scope
protocol-v2 on-chain program; implementation security, architecture, business logic, economic attacks, and authority structure. Reviewed revisions b8283103… through 0ee9e960…; some changes were only partially reviewed.
Findings
1 Critical, 0 High, 2 Medium, 4 Low, 3 Informational. Critical issue: cranker fee accounting could enable theft over time; two Medium issues affected margin and pause/deposit/withdraw restrictions. ([neodyme.io](https://neodyme.io/reports/Drift.pdf))
Fix status
Most findings were resolved and fixes were verified by Neodyme; some items were acknowledged or pending merge in the report. Covers audited source revisions, not proven current deployed bytecode. Bytecode match: Not verifiable as of September 5, 2026.
Evidence (1)

audit

one source

OtterSec conducted an assessment of Drift Labs’ snap-solana program in August 2023, a MetaMask Snap that connects MetaMask to Drift and enables trading on Drift from within MetaMask. This is an auxiliary interface/security component, not the core on-chain protocol, but affects user transaction UX and safety.

Auditor
OtterSec
Report date
2023-08-04
Scope
MetaMask **snap-solana** integration for Drift: code at GitHub commit 04fa431, focusing on transaction display, wallet interaction, and user safety; excludes core Solana protocol programs.[3]
Findings
The OtterSec snap audit produced **3 suggestions** (no critical/high/medium findings) focused on improving how crucial transaction details are displayed to users before approval, to mitigate potential user financial loss from blindly approving transactions.[3]
Fix status
The report provides recommendations; Drift states that suggestions were incorporated to improve UX and safety, but this remains an **unverified marketing claim** without independent confirmation.[3][5] Coverage of the current deployed snap code versus audited commit 04fa431 is Not verifiable as of 2026-09-04.
Evidence (3)

audit

one source

Following the April 2026 $285M incident, Drift announced a full protocol reboot with security as the foundation, contingent on completion of two independent audits: OtterSec (full codebase redesign and audit) and Asymmetric Research (operational security, mitigation of exploited vulnerability, and org-wide security enhancements).

Auditor
OtterSec & Asymmetric Research (planned relaunch audits)
Report date
2026-04-16
Scope
Planned: complete redesign and full audit of new Drift on-chain codebase (OtterSec) plus operational security review (Asymmetric) covering key management, infrastructure, and access controls; post‑incident remediation program rather than legacy deployed code.[10][4]
Findings
As of the latest available information, no finalized public audit reports for the relaunch codebase from OtterSec or Asymmetric have been published; therefore, specific critical/high/medium findings are Not verifiable as of 2026-09-04.[10]
Fix status
Drift states that relaunch is contingent on completion of these audits and hardened operational practices, but without public reports or on-chain verification, remediation status across components is Not verifiable as of 2026-09-04.[10]
Evidence (2)

audit

unverified

Drift Protocol’s docs say Trail of Bits audited the decentralized exchange and smart contract from November 7 to December 2, 2022, and then reviewed fixes from January 23 to January 25, 2023. The reported result says no high-severity flaws were found, but the report also notes unresolved or partially resolved findings on page 73 and an undetermined finding related to production testing code on page 77.

Auditor
Trail of Bits
Report date
2022-11-07
Scope
Drift Protocol decentralized exchange and smart contract (protocol-v2)
Evidence (1)

audit

two sources

Trail of Bits performed a security audit of Drift Protocol’s decentralized exchange smart contracts on Solana. The engagement ran from November 7 to December 2, 2022, focused on the core on-chain DEX logic and associated programs, not operational security or key management.

Auditor
Trail of Bits
Report date
2022-12-02
Scope
Core Drift DEX / perpetual futures smart contracts on Solana (protocol v1/v2 base), static code review at fixed commits; excludes governance, key management, infrastructure, and off-chain components.[1][8][11][15]
Findings
According to Drift’s audit documentation and the Trail of Bits report, the audit "did not uncover any high-severity flaws" affecting confidentiality, integrity, or availability; findings were limited to lower‑severity issues and best‑practice improvements.[1][8] No critical issues were reported.[1][8]
Fix status
Drift states that all identified issues were addressed prior to or as part of the protocol v2 rollout; however, this is based on protocol documentation and counts as an **unverified marketing claim** absent independent confirmation.[1][13] The 2026 $285M incident was explicitly characterized in independent analyses as an operational key compromise outside the scope of this smart‑contract audit.[11][15] Bytecode‑match to currently deployed programs on Solana is Not verifiable as of 2026-09-04.
Evidence (4)

audit

unverified

The audit result is summarized by Drift as: no high-severity flaws affecting confidentiality, integrity, or availability were uncovered. Fix status: Trail of Bits reviewed the implemented fixes and mitigations in late January 2023. Covers deployed code: the docs state the audit was conducted with access to the source code and documentation, but the public page alone does not prove bytecode-to-deployment matching; the Bytecode-match note is not verifiable from the provided sources.

Auditor
Trail of Bits
Report date
2023-01-23
Scope
Fix review for previously identified Drift issues
Evidence (1)

Team & Reputation

founders

two sources

Drift is a publicly led, non-anonymous DeFi derivatives protocol on Solana, founded in 2021, with a real venture-backed operating company (Drift Labs) and a visibly identifiable leadership team. ### Founders & key team

  • Cindy Leow – Co‑founder and CEO / core contributor.
  • Background in investment banking and crypto trading; active in the space since ~2016.
  • Public presence (conference talks, podcasts, TOKEN2049 panels, Forbes 30U30, LinkedIn).
  • Described as co‑founder of Drift Labs and Drift Protocol, and key face of the project.
  • David Lu – Co‑founder and core contributor.
  • Product / venture capital background; co‑founder of Drift Labs with Leow.
  • Public speaker at TOKEN2049 Dubai announcing DRIFT governance token.
  • Other co-founders / contributors
  • Several sources mention four founders and refer to additional/anonymous quant and engineering co‑founders, including names like Chris Heaney in podcasts and educational content.
  • Some media also attribute co‑founder status to Cyrus Younessi, ex‑MakerDAO, though this appears in one secondary article and is not consistently corroborated across major profiles. ### Prior projects, track record, incidents
  • Leow has prior experience in crypto arbitrage and trading; Lu has VC/product experience.
  • Public materials highlight Drift’s growth (largest perps DEX on Solana at times, large TVL) and multiple funding rounds (seed and Series A) led by notable crypto VCs and Solana founders.
  • No credible records in retrieved sources of protocol‑level hacks or catastrophic failures specifically attributed to Drift. Any mention of “hack” in relation to individuals (e.g., Younessi) appears in narrative/educational content and is not clearly tied to a confirmed exploit of Drift itself. ### Public vs anon, office, jurisdiction, “real business” check
  • Team is largely public (Leow, Lu and others with conference appearances and LinkedIn profiles).
  • Drift operates via Drift Labs, a corporate entity described as a crypto company building the protocol; Fortune and other media treat it as a standard VC‑backed startup.
  • One guide states Drift has headquarters in Australia while being globally used. This is a single-source claim; corporate registration details are Not verifiable as of 2026‑09‑04.
  • Funding from major VCs and Solana founders, plus ongoing public events and hiring signals, support that this is a real operating business, not a pure web‑front shell. ### Credibility assessment (institutional lens)
  • Positives: non‑anonymous founders, repeated coverage in independent media, major VC backing, ongoing conference presence, and clear corporate branding via Drift Labs.
  • Gaps/risks: incomplete clarity on full cap table and exact legal domicile structures; mixed/secondary reporting on the wider founding team and any past personal incidents. Key corporate registry details are Not verifiable as of 2026‑09‑04.
Evidence (13)

general reputation

two sources

Drift Protocol’s reputation is currently severely impaired after a major 2026 exploit, though available evidence points to social‑engineering and key‑management failure rather than an intentional fraud or rug pull. Protocol & founders Drift is a Solana-based decentralized perpetual futures exchange that grew into one of the largest DeFi derivatives platforms on Solana. Public coverage focuses on the protocol rather than individual founders; detailed founder bios are not prominent in major news or analysis, which is a minor transparency gap as of 2026. Not verifiable as of [2026-09-04] for specific founder identities and track records. Audits & security posture (pre‑hack) A 2026 review notes multiple audits by Trail of Bits, OtterSec, and Neodyme across 2022–2024, primarily covering core protocol Solana programs and v2 upgrades.

This supports a reputation of robust code auditing, but the April 2026 incident exploited privileged access / admin key infrastructure, not an on-chain code bug. Major exploit & impact on reputation On April 1, 2026, Drift was drained of about $285–286M (over 50% of its TVL) in roughly 12 minutes via a coordinated attack leveraging compromised administrator keys, fake collateral, manipulated oracles, and durable nonce–based pre‑signed transactions. Multiple independent forensics firms (TRM Labs, Chainalysis, Elliptic, PeckShield) and media outlets attribute the attack likely to North Korean–linked groups (Lazarus / UNC4736), emphasizing social engineering of contributors and multisig signers rather than protocol code defects. Drift’s own public communications describe a “novel attack involving durable nonces” and compromised Security Council admin powers, acknowledging that one contributor may have been compromised via a malicious repository clone. Fraud / rug / insolvency / legal-regulatory

  • There is no evidence in reputable sources of Drift’s founders stealing funds, orchestrating a rug, or misrepresenting the exploit as something it was not; the narrative consistently frames it as an external, state‑linked attack.
  • No public reports of formal regulatory enforcement actions, sanctions, or criminal charges against the protocol or team were identified as of 2026-09-04. Not verifiable as of [2026-09-04] for any non-public investigations.
  • Post‑hack, TVL dropped sharply (e.g., from ~$550M to under $250M per analytics), highlighting severe trust damage and user losses, but insolvency proceedings or wind‑down announcements are not reported. Sentiment, criticisms, unresolved concerns
  • Community and analyst sentiment focuses on failures of key management, governance controls, and social‑engineering resilience, rather than smart‑contract code quality.
  • Critical commentary highlights: concentration of admin power, zero‑timelock migration path, and inadequate safeguards around durable nonces and signer workflows.
  • Key unresolved concern: how Drift will redesign governance, key infrastructure, and vault safety, and whether affected users will be made whole; no comprehensive compensation or recovery plan is verifiable as of [2026-09-04]. Overall, Drift’s prior image as a heavily audited, leading Solana perps DEX is now overshadowed by the 2026 admin‑key exploit and large user losses, creating high reputational and governance risk despite no clear evidence of internal fraud or regulatory sanctions.
Evidence (15)

Economy

TVL: $643K

model

one source

Economic model — Drift Trade (Solana)

  • Strategy / assets in-out: Perpetuals-first trading venue, with spot, borrow/lend, insurance/liquidity and staking-adjacent products. Users deposit primarily USDC, SOL and other supported collateral; withdrawals return collateral or product principal/rewards, subject to margin, liquidation, liquidity and account constraints. It is not a single passive-yield vault.
  • Yield source: Trading fees, funding-rate transfers, liquidation-related flows and—where applicable—SOL staking rewards plus product fees. Keeper incentives consume part of execution/liquidation fees; liquidation rewards are reported at 0.75%–3% by market.
  • Organic vs subsidized: Trading-fee revenue is usage-derived organic revenue. Incentives, trading rewards and ecosystem allocations can subsidize user returns; the organic percentage is not verifiable as of September 6, 2026. Drift’s tokenomics materials explicitly include trading rewards and liquidity incentives.
  • Risk posture: Core perps activity is directional and leveraged, not market-neutral. LP, insurance-fund and vault participants may have counterparty, inventory, liquidation and smart-contract exposure. No restaking exposure identified; SOL staking creates validator/network exposure.
  • Leverage / looping: Perpetual positions support leverage; current documentation lists up to 20x initial leverage for several major markets and higher maintenance-equivalent limits, but portfolio-wide realized leverage is not verifiable as of September 6, 2026.
  • Lockups / withdrawals / gates: Ordinary trading collateral is generally withdrawable when account health permits. Product-specific cooldowns, withdrawal gates and limits are not verifiable as of September 6, 2026.
  • Fees / revenue: Trading, borrow/lend, deposit/withdrawal, staking/management and liquidation-related fees may apply. DeFiLlama attributes Drift Trade revenue to protocol treasury/token-holder flows, while Drift Staked SOL revenue includes withdrawal and management fees; these are analytics classifications, not raw on-chain verification.
  • TVL: DeFiLlama currently displays Drift Trade TVL of approximately $642.6k, 100% Solana, with cumulative fees of $41.1m and cumulative revenue of $31.04m; recent 30-day fees/volume display as $0. Dune cross-check, product split, trend and latest-block TVL are Not verifiable as of September 6, 2026.
  • APY sustainability: Drift Trade has no protocol-wide APY; returns depend on trading PnL/funding and are highly volatile. Staked-SOL yield is variable and linked to staking economics. Historical APY volatility and sustainability are Not verifiable as of September 6, 2026. Contradiction / data-quality callout: DeFiLlama shows substantial cumulative activity but zero recent fees and perp volume; this conflicts with a normal live-operations interpretation and requires raw on-chain reconciliation.
Evidence (4)

reserves

one source

Assessment as of September 6, 2026: Dune/on-chain verification is unavailable in this run; therefore wallet balances, treasury addresses, and current custody balances are Not verifiable as of September 6, 2026.

  • Liquid reserves: No separately reported, independently attested treasury balance was identified. Drift’s April 16 incident disclosure listed residual assets after the exploit, including 8,743,353 DRIFT, 474,184.82 USDC, 141.45 USDT, 65.34 SOL, and numerous other tokens, but provided no aggregate USD valuation. The Insurance Fund was stated to be unaffected, with deposits available for withdrawal by July 7, 2026; its size was not disclosed.
  • Liabilities: Drift disclosed approximately $295 million of outstanding user losses arising from the April 1, 2026 exploit. This is a disclosed recovery obligation, not an audited balance-sheet liability.
  • Addresses / composition: Specific treasury, insurance-fund, recovery-pool, or custody addresses were Not verifiable as of September 6, 2026. The disclosed remaining-asset list is composition evidence, but not proof of current balances.
  • Custody and control: Drift stated that relaunch would use a new community-governed multisig for core protocol assets, with dedicated signing devices, timelocks, external transaction verification, and disabled durable nonces. This describes the proposed post-incident control framework; operational deployment was not independently verified.
  • Reserve policy: The Insurance Fund is intended to backstop trading-related bankruptcies and is funded by stakers and protocol fee sources; asset pools are denomination-specific. This is a policy description, not evidence of current solvency.
  • Attestations: No independent reserve attestation or proof-of-reserves report was found. Not verifiable as of September 6, 2026. Contradiction / data-quality callout: The previously recorded DeFiLlama snapshot of $5.35m TVL is superseded by a current DeFiLlama page showing $286.72m TVL on Solana. Neither figure represents treasury or liquid reserves, and neither is on-chain verified here. Conclusion: Reserve transparency is materially inadequate after the exploit. The only quantified obligation is roughly $295m of user losses; liquid reserves, reserve coverage, custody addresses, and attested solvency remain unverified.
Liabilities usd
$295.0M
Evidence (5)

tokenomics

two sources

DRIFT tokenomics — Solana; reviewed September 4, 2026.

  • Native token/address: Drift’s native governance token is DRIFT; Solana SPL mint DriFtupJYLTosbwoN8koMbEYSx54aFAVLddWsbksjwg7.
  • Supply/valuation: Maximum and total supply are 1.0B DRIFT. Current aggregator data conflicts: CoinMarketCap reports 611.5M circulating, ~$0.01219 price, $7.46M market cap / $12.19M FDV; CoinGecko reports roughly 720M circulating, $8.62M market cap / $12.06M FDV. Treat supply and valuation as analytics estimates, not on-chain verified.
  • Utility/governance: DRIFT is primarily a governance/voting asset. The DAO’s Realms branch handles development/tokenomics; the Security Council can set fees, risk parameters, markets and upgrades; Futarchy funds ecosystem grants. DRIFT may also receive fee discounts, and staking proposals/mechanics are governance-controlled.
  • Revenue share/buybacks/burns/staking: No confirmed DRIFT revenue-sharing, buyback, or burn mechanism was identified. Drift’s insurance-fund staking yields are tied to vault activity and are not equivalent to DRIFT staking rewards. Not verifiable as of September 4, 2026 whether any DRIFT-specific staking program is active.
  • Emissions/unlocks: Five-year emission schedule from the May 2024 TGE. Allocation: Community 53% (Ecosystem/trading 43%, launch airdrop 10%), Protocol Development 25%, Strategic Participants 22%. Team/contributor terms: 18-month lock then 18-month linear vesting; investor cliffs were reported as passed by November 2025, with Series B vesting continuing. Whether announced unlocks actually occurred on-chain: Not verifiable as of September 4, 2026.
  • Controls/concentration: Mint and freeze authority are reported revoked; a standard SPL token has no native blacklist or fee switch. Who controls protocol fee changes: Security Council/DAO governance. Top-holder concentration, insider-wallet attribution, and exact treasury ownership: Not verifiable as of September 4, 2026.
  • Liquidity/listings: Main Solana venues include Jupiter-routed markets, Orca, Meteora, Raydium and Phoenix; observed individual pool liquidity is generally thin (roughly tens of thousands of dollars), creating material slippage risk. Risk conclusion: DRIFT has capped supply and revoked token-level mint/freeze powers, but current supply figures conflict materially across aggregators, while holder concentration and realized unlocks lack raw on-chain verification in this run.
Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin fall below $10,000 would likely be a severe risk-off shock for Drift Trade on Solana, with the main expected impacts being sharply lower trading activity, reduced open interest, higher liquidation frequency, and elevated stress on collateral and insurance/defense mechanisms. However, the exact protocol-specific loss path is Not verifiable as of 2026-09-04 from the available web sources, because the results do not provide current on-chain exposure, vault balances, or liquidation parameters for Drift. Drift is a Solana-native perpetuals and margin platform with a risk engine that monitors positions 24/7, and public descriptions say it supports cross-margined perpetual futures, spot trading, lending/borrowing, and leverage up to 101x in some contexts.

The available reporting also shows Drift has recently faced major operational stress: multiple sources describe an April 2026 exploit/attack that forced deposits and withdrawals to be suspended and caused substantial losses, with estimates ranging roughly from $200 million to $285 million. That means the protocol’s resilience under another extreme market shock would depend heavily on post-incident recovery status and current solvency buffers, which are not independently verifiable from the provided results. For a BTC <$10,000 scenario, the most plausible protocol-level outcomes are:

  • User behavior shock: lower perp volume and fee revenue as Solana market activity contracts.
  • Margin shock: more liquidations and wider spreads if BTC-linked and SOL-linked positions move against traders.
  • Collateral stress: increased pressure on account health and insurance-style backstops if collateral values fall broadly.
  • Confidence shock: further withdrawal/deposit caution if users perceive correlated market and protocol risk. What cannot be verified from the current sources is whether Drift’s current liquid supply, insurance/recovery pool, or risk parameters are sufficient to absorb such a drawdown; that is Not verifiable as of 2026-09-04. The web results also do not provide a chain-specific exposure breakdown or a measured TVL/reserve figure for Solana at this time, so any numeric estimate would be speculative.
Evidence (6)

stress scenario - largest collateral depegs 20%,

two sources

For Drift on Solana, a 20% depeg in the largest collateral is primarily a margin and liquidation stress, not a protocol-level solvency number I can verify from the provided sources. Drift states that account health is based on collateral versus maintenance margin, and that when health reaches zero the account becomes liquidatable; it also notes that users can use any token as collateral and that collateral is weighted in the margin system. What can be said from the sources is that depegs are explicitly recognized as a risk for liquid staking collateral, and Drift says a 20% drop in mSOL can trigger liquidations at up to 3x leverage.

Drift also uses a 10% oracle-TWAP/mark divergence band that can prevent order fills during volatile events, which may slow re-hedging or deleveraging under stress. However, the system-wide impact of a 20% depeg of the single largest collateral is Not verifiable as of 2026-09-04 from the provided web results, because the sources do not give the on-chain collateral mix, exposure weights, open interest by collateral, or insurance-fund coverage needed to quantify aggregate losses. Operationally, the likely failure mode is: collateral value falls, affected accounts cross maintenance margin, liquidations cascade, and any shortfall would first rely on insurance mechanisms; Drift’s borrow-lend FAQ says that if insurance is insufficient, losses can be socialized across depositors.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

unverified

For Drift Trade on Solana, the insolvent counterparty path is: a trader’s position is liquidated first; if the fill cannot cover the debt, the remaining shortfall is absorbed by the Insurance Fund, which is explicitly designed to maintain solvency in liquidation/bankruptcy events. The liquidator receives the liquidation fee/discounted execution economics, while the Insurance Fund takes the first-loss on any bad debt beyond what the position collateral covers. Expected loss path: adverse price movement pushes margin below maintenance; a liquidator bot closes or reduces the position; if the market gaps through the liquidation price, the position can end with negative equity; that deficit flows to the Insurance Fund rather than to other users directly. Drift’s v0 design also states that liquidation penalties are split between the liquidator and the Insurance Fund, and that losses beyond zero margin are borne by the Insurance Fund. Who compensates whom: the protocol compensates the liquidator with the penalty/fee, and the Insurance Fund compensates the venue by covering the insolvent account’s unpaid obligation.

Insurance Fund depositors are then exposed to that first-loss risk, but they earn a share of protocol revenue/liquidation fees as compensation for staking capital into the fund. Impact path through smart contracts: liquidation is executed by on-chain liquidation/liquidator logic; the settlement path routes the position through the liquidator, applies the market-specific penalty, and then charges any residual bad debt against the Insurance Fund vault/accounting layer. Drift’s docs also describe separate Insurance Fund vaults per asset and an unstake/withdraw workflow with a cooldown, showing the fund is an explicit on-chain reserve rather than an off-chain backstop. Not verifiable as of 2026-09-04: the exact current vault balances, chain-specific exposure percentages, and whether the fund is sufficient under a severe multi-account insolvency shock require on-chain verification, which is unavailable in this run.

Evidence (5)

stress scenario - committed fraud by the DAO or owners

two sources

For a stress scenario of committed fraud by the DAO or owners, Drift Trade is not directly supported by the available sources as an insider-fraud case. The strongest evidence instead points to an external social-engineering/governance compromise in which attackers obtained privileged administrative control and drained about $285 million from the protocol, rather than the DAO or owners intentionally committing fraud. What can be said with confidence is that the incident involved privileged access abuse, pre-signed administrative transactions, and governance-layer failure; multiple independent sources describe it as a sophisticated attack on Drift’s Security Council and admin controls, not an allegation of fraudulent intent by the protocol’s owners.

So, if your stress-test question is whether there is evidence that the DAO/owners committed fraud, the answer is: Not verifiable as of 2026-09-04. If the question is whether the protocol suffered a severe loss event that could be modeled as an insider-compromise/fraud-style scenario, the answer is yes in operational impact, but the public reporting attributes it to attackers, not insiders acting fraudulently.

Evidence (5)

stress scenario - primary yield source negative 30d,

two sources

Drift Trade does have yield-bearing products, but for a stress scenario with the primary yield source negative over 30 days, the main risk is that deposit APY can turn negative or distributions can be insufficient to offset fees and losses, especially in Market Making Vaults and Insurance Fund Staking. Drift’s own Earn page says Market Making Vaults carry a risk of negative performance in challenging market conditions, and Insurance Fund Staking can also experience negative performance if the platform sees large liquidations. For Drift’s yield stack, the relevant sources of return include lending, insurance-fund revenue, SOL liquid staking, and trading strategy vaults.

That means a negative 30-day primary yield source does not imply the whole protocol is failing; it means the specific product’s return stream is under stress while other Earn products may still be positive. As a risk lens, the most exposed areas are:

  • Market Making Vaults: explicitly documented as having negative-performance risk in adverse markets.
  • Insurance Fund Staking: can be hit if liquidations spike and losses exceed fee income.
  • Borrow/Lend and staking products: generally lower-risk than strategy vaults, but still subject to market, utilization, and platform risks. What is not verifiable as of 2026-09-04 from the available sources is the current 30-day return for any specific Drift vault, whether the primary yield source is presently negative, or whether that negative performance is material at the protocol level. The web results show product design and risk disclosures, not an as-of 30-day performance breakdown.
Evidence (3)

Governance & Legal

governance

two sources

Assessment as of September 13, 2026: Drift has a real governance layer, but it is not demonstrably sovereign over all development, contracts, frontend, or funds. The published design uses three branches: Realms DAO for broad protocol decisions and Security Council elections; a Security Council for risk parameters, markets, fees, and program upgrades; and a Futarchy DAO for grants. The Foundation coordinates execution; Webslinger was named DAO administrator and Matt Shaw independent director.

Proposal process: proposals are discussed through Drift governance forums and then submitted to Realms voting; delegate programs and quorum changes have also been proposed through the forum. A 2025 proposal stated that four prior Realms votes passed with under 0.5% total-token participation, indicating materially concentrated/low-participation governance. Top DRIFT holders, voting concentration, and current delegation cannot be verified without Dune: Not verifiable as of September 13, 2026.

Security finding: before the April 1, 2026 exploit, the Security Council was reported as a 2-of-5 multisig with upgrade and administrative powers. Two signers were socially engineered through durable-nonce approvals, enabling rapid administrative takeover and approximately $285 million in losses. This demonstrates that the multisig could move or expose user funds without a fresh token-holder vote.

Drift subsequently announced a redesigned community multisig, mandatory timelocks for critical actions, and removal of durable nonces, but did not publish a verifiable current signer list, threshold, or delay in the reviewed sources. [CONTRADICTION] Drift markets governance as community-driven, yet the Security Council—not direct token-holder voting—held direct upgrade/risk authority, and historically operated with a low 2-of-5 threshold and zero timelock. The new post-incident controls are announced but not independently verifiable here. Company/entity: Drift DAO Foundation, Webslinger, Matt Shaw, jurisdiction, registration number, directors beyond the named individual, and applicable app Terms of Service: Not verifiable as of September 13, 2026.

Dao governance
No
Evidence (5)

legal & regulatory

two sources

As of September 4, 2026, Drift Trade is identifiable as the Solana-based Drift Protocol, with Drift Labs described as a core contributor and Drift Foundation supporting governance/ecosystem functions. A Korean exchange due-diligence report identifies Drift Protocol Corp. as the operating/issuing corporation and Drift Foundation as Cayman Islands-based; the corporation’s jurisdiction was not disclosed. Current status / legal structure. The supplied app URL currently redirects to Velocity Exchange, indicating a rebrand or successor-front-end rather than ordinary continued Drift operation.

Drift’s own 2026 updates describe a major April 1, 2026 exploit, protocol pause, law-enforcement engagement, recovery process, and planned relaunch. ToS, restrictions, KYC/AML. Drift publicly stated that access was limited to certain jurisdictions, but the current prohibited-country list and enforceable terms were not retrievable. Not verifiable as of September 4, 2026. Historical third-party descriptions report wallet-based, no-KYC access, but this should not be treated as confirmation of current legal availability or AML controls. Classification / regulatory risk. The product historically offered perpetual futures, leverage, spot, lending and vaults.

Perpetual derivatives may constitute regulated derivatives or an exchange activity depending on the user’s jurisdiction; no evidence was found of Drift holding a U.S. CFTC/SEC registration. Token classification remains jurisdiction-specific; a Korean listing report labels DRIFT a utility token, which is not determinative elsewhere.

Warnings, enforcement and litigation. No regulator enforcement action against Drift Protocol, Drift Protocol Corp., or Drift Foundation was found. The April 2026 exploit is a major operational/legal risk, but is not itself regulatory enforcement. A Massachusetts class action, *McCollum v.

Circle*, targets Circle over alleged failure to freeze stolen USDC—not Drift itself. Sanctions / data protection. No evidence was found that Drift or its entities are themselves sanctioned. Exact Drift privacy-policy/controller details and GDPR/CCPA compliance are Not verifiable as of September 4, 2026; on-chain activity is publicly observable and practically immutable.

Legal structure does not eliminate attribution, consumer-protection, derivatives, sanctions, or negligence exposure for identifiable contributors and entities.

Active enforcement
No
Sanctioned
No
Entity
Drift Protocol Corp.; Drift Foundation
Jurisdiction
Drift Foundation — Cayman Islands; Drift Protocol Corp. — Not verifiable as of September 4, 2026
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Drift Protocol Corp', 'Drift Foundation', 'Drift Trade'. OFAC SDN screening of 'Drift Protocol Corp', 'Drift Foundation', 'Drift Trade': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Drift Protocol Corp
  • Drift Foundation
  • Drift Trade
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Drift Trade does not appear to issue its own stablecoin; the protocol’s settlement asset was USDC and later shifted to USDT, so own_stablecoin is false. No verifiable evidence was found that the stablecoin used by Drift ever depegged, so stable is true; depeg_count, max_depeg_pct, and last_depeg_date are Not verifiable as of 2026-09-06.

Own stablecoin
No
Stable
Yes
Stablecoin ids
  • USDC
  • USDT
Evidence (2)

Risks & Strengths

risks

one source

Drift Trade’s dominant risk is control-plane security: on April 1, 2026, attackers reportedly drained approximately $285 million through multisig compromise, durable-nonce abuse, and collateral/oracle manipulation. Recovery and relaunch controls are proposed but not independently verified; current TVL, exposure, and live contract state are Not verifiable as of September 5, 2026. Contradiction: Drift cites approximately $295 million in outstanding user losses, while BlockSec estimates approximately $285.3 million stolen; the difference likely reflects accounting scope, but remains unresolved.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Administrative key compromiseA compromised signer or social-engineering campaign can authorize withdrawals, alter markets, or bypass protocol safeguards, as demonstrated by the April 2026 incident.HighHighProposed dedicated signer devices, independent transaction verification, timelocks, real-time alerts, disabled durable nonces, a new community multisig, and independent audits.High: controls are proposed/relaunch-dependent and have not been independently verified as live.
Oracle and collateral manipulationManipulated or thinly traded collateral can create false account equity, enable excessive borrowing, and transfer losses to the insurance fund or other users.HighMediumPlanned redesign of market parameters, liquidation logic, oracle protections, and independent review by security and risk specialists.High: the failure mode was exploited in production; post-relaunch implementation is Not verifiable as of September 5, 2026.
Perpetual insolvency and socialized lossLeveraged liquidations, vAMM deficits, or borrower defaults can exceed collateral and insurance capacity, impairing depositors and potentially socializing losses.HighMediumAsset-specific insurance-fund vaults, liquidation mechanisms, fees, and bankruptcy backstops.High: fund size, asset matching, and current solvency are Not verifiable as of September 5, 2026.
USDT settlement concentrationMigrating settlement from USDC to USDT concentrates settlement, liquidity, and issuer/counterparty exposure in one stablecoin ecosystem.MediumMediumPlanned Tether support facility and designated market makers for relaunch liquidity.Medium: liquidity support does not remove issuer, freeze, depeg, or regulatory risks.
Recovery and relaunch executionRecovery depends on future exchange revenue, partner funding, claims administration, and successful redevelopment; delays or weak adoption could leave users materially under-recovered.HighHighProposed recovery pool, transferable recovery token, forensic investigation, staged relaunch, and audit gates.High: recovery amounts, timing, relaunch status, and enforceability are Not verifiable as of September 5, 2026.
Evidence (4)

strengths

two sources

Drift Trade’s top five strengths are: fast execution on Solana, capital efficiency through cross-margining, deep liquidity with low slippage, non-custodial/on-chain transparency, and robust risk management. These are the most consistently supported differentiators across independent sources, though some high-level marketing claims (for example, exact leverage limits) vary by source and should be treated cautiously.

  • Fast execution and low fees: Multiple sources describe Drift as built on Solana, benefiting from sub-second finality and low transaction costs, which makes active trading and frequent order flow more efficient.
  • Capital efficiency via cross-margin: Drift’s core architecture uses a cross-margined risk engine and unified collateral, allowing users to reuse collateral across positions and markets.
  • Deep liquidity and low slippage: Drift combines AMM liquidity, just-in-time auction liquidity, and order-book style matching to improve fill quality and reduce price impact, especially on larger trades.
  • Non-custodial, on-chain transparency: Independent descriptions emphasize that deposits, withdrawals, and trades are executed on-chain, with users retaining self-custody of their Solana wallet assets.
  • Risk controls and liquidation infrastructure: Drift is repeatedly described as having a robust risk engine, oracle-based pricing, insurance-style protections, and liquidation mechanisms designed to handle volatile markets more safely.
Evidence (11)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 23 two independent sources, 11 one source, 6 unverified.
  • Oldest fact verification date: 2026-08-29.