We Watched $285 Million Leave Solana in 12 Minutes. Here’s What We Did About It.
By MAGMA Protocol — ExiDante Corp — April 3, 2026
We Watched $285 Million Leave Solana in 12 Minutes. Here’s What We Did About It.
By MAGMA Protocol — ExiDante Corp — April 3, 2026

This is not an April Fools joke. Drift explicitly said so. It was the largest DeFi hack of 2026 and the second-largest exploit in Solana history.
We are MAGMA Protocol. We are building a Yield-Bearing Narrative Capital Market on Solana. We are pre-mainnet. And we need to tell you exactly what we think happened, why it concerns us directly, and what we are doing about it.
What Actually Happened to Drift
The attack was not a smart contract bug. Trail of Bits audited Drift in 2022. ClawSecure audited them in February 2026. Both passed. The attack bypassed all of it through three simultaneous vectors.
Durable nonces. This is a legitimate Solana feature that allows transactions to be signed in advance and submitted later, bypassing the normal short expiry window. The attackers social-engineered two legitimate multisig council members into pre-signing administrative transfer transactions — transactions the signers apparently did not fully understand. Those signatures were held for 21 days, then submitted. In 12 minutes, the attacker had full administrative control of the protocol.
A fake token. The attacker manufactured CarbonVote Token (CVT) with a few thousand dollars in seeded liquidity and wash trading. Drift’s oracle priced CVT as legitimate collateral worth hundreds of millions of dollars. The attacker deposited CVT and withdrew real assets against it.
Zero-timelock governance. A recent governance change had introduced a Security Council with zero timelock — meaning decisions took effect instantly. Once the pre-signed transactions were submitted, there was no window for the team or community to intervene.
TRM Labs and Elliptic attribute the attack to North Korean state-sponsored hackers (Lazarus Group). The staging began March 11. The execution was April 1. Three weeks of preparation, invisible to monitoring systems, culminating in 12 minutes of destruction.
Why This Directly Concerns MAGMA
We are building a protocol where users commit capital to narrative conviction markets. That capital earns DeFi yield through integrations with lending protocols including Kamino Finance, Jupiter Lend, Save Finance, and Meteora.
Drift Protocol was in that list.
As of April 3, 2026, Drift has been removed from our yield router. No MAGMA user capital will be routed to Drift until the protocol has completed a full postmortem, independent re-audit, and demonstrated safe operation. This cost us nothing — we are pre-mainnet and no user funds are at risk. But the decision reflects a principle we are making explicit today: protocols earn routing access through demonstrated security, not TVL.
The Drift attack also validated a core architectural decision we made months ago. MAGMA’s oracle resolution system uses a weighted consensus of eight independent sources — Grok, Tavily, Pyth Network, Ruma, Perplexity, PandaScore, RedStone, and Switchboard — because we recognized that any single oracle can be manipulated. The Drift attack demonstrates exactly this. A single oracle priced a fake token as legitimate collateral. A multi-source consensus system with structural validation would have rejected CVT as collateral because no independent source would have corroborated its valuation.
What We Are Doing About It
A New Layer of Security — Operational Audit
Our security program has always had four layers: design review, contract audit with test suite, live testnet adversarial simulation, and formal external audit. Today we are adding a fifth: operational security audit.
Code audits do not catch operational security failures. They do not assess how keys are managed, whether multisig signers understand what they are approving, whether governance timelocks are adequate, or whether the team has procedures for identifying durable nonce transactions before signing. A separate operational security assessment — by a firm with specific expertise in this domain — is now a non-negotiable gate before MAGMA mainnet.
The Durable Nonce Prohibition
MAGMA will never use durable nonce transactions for administrative operations. This is a written protocol policy effective today. Any durable nonce transaction submitted to a MAGMA multisig must be rejected and reported. All administrative transactions will be constructed, reviewed, and submitted in the same session with standard nonces. Multisig signers will be trained to identify durable nonce transactions before any signing authority is granted.
The Multisig Roadmap
We are accelerating our multisig implementation. Before testnet opens to external users, all oracle authority and upgrade authority operations move to a 2-of-3 Squads multisig. At mainnet, this becomes a 3-of-5 multisig with two external independent signers, 100% hardware wallet requirement, geographic distribution of signers, and a 48-hour minimum timelock on all non-emergency governance changes. Post-TGE, we target a 5-of-7 structure with community-elected signers and MetaDAO futarchy for major protocol parameter decisions.
Zero-timelock governance is prohibited at every stage of our protocol lifecycle. No exceptions.
The Protocol Vetting Framework
Going forward, every DeFi protocol integrated into MAGMA for yield routing must meet a structured set of criteria: two or more independent audits, audit within six months of integration, 48-hour minimum timelock on governance, no single-point admin key, multi-source oracle with token whitelist for collateral, insurance fund covering more than 5% of TVL, and an active public bug bounty. All criteria are mandatory. The era of “add them because they have good TVL” is over.
Why We Will Not Rush Mainnet
We are planning a community ICO on futard.io to fund the Layer 4 formal audit. This timing is intentional. The ICO funds the audit, and the audit gates the mainnet. ICO participants are directly funding the security work that protects their investment.
But the ICO does not create a mainnet deadline. The audit does. We will not compromise the second to satisfy pressure from the first.
MAGMA’s testnet will run for a minimum of 90 days. During that time, oracle accuracy must exceed 90% on 100 or more real resolved narratives. The Echo Pool must distribute successfully for three or more epochs. Our Sybil detection system must be operational and verified. Any critical security incident resets the clock.
Drift had two audits. The attack came from a direction neither firm was looking. We have five security layers, an operational security audit, a 90-day testnet gate, and a durable nonce prohibition. We are not claiming to be unhackable. No protocol can make that claim. We are claiming that when user capital enters MAGMA Protocol, we will have done more systematic security work than the overwhelming majority of protocols that came before us.
The Honest Statement
The Solana ecosystem took a serious blow on April 1, 2026. A protocol trusted by its users lost $285 million in 12 minutes, and the attackers were likely state-sponsored actors with three weeks of preparation. This is the security environment we are building in.
We are not celebrating this. We are not using it to make ourselves look good. We are documenting our response because we believe the community deserves to know exactly where protocols they might interact with stand on security — before they commit capital, not after they lose it.
MAGMA Protocol will launch when it is safe to launch. Not before.
MAGMA Protocol is a Yield-Bearing Narrative Capital Market currently in development on Solana. We are pre-testnet. No user funds are at risk. If you want to follow our security-first development journey, join our waitlist at magmaprotocol.xyz and our Discord.
Full Security Position Statement PDF available at magmaprotocol.xyz
Tags: #Solana, #DeFi, #Security, #Drift Protocol, #Smart Contract Audit, #Multisig, #Oracle Security, #MAGMA Protocol
메타데이터
- post_id
- f18ec2f73e08
- slug
- we-watched-285-million-leave-solana-in-12-minutes-heres-what-we-did-about-it-f18ec2f73e08
- url
- https://medium.com/@magma-protocol/we-watched-285-million-leave-solana-in-12-minutes-heres-what-we-did-about-it-f18ec2f73e08
- canonical_url
- https://medium.com/@magma-protocol/we-watched-285-million-leave-solana-in-12-minutes-heres-what-we-did-about-it-f18ec2f73e08
- author_url
- https://medium.com/@magma-protocol
- status
- ok
- fetched_at
- 2026-06-25 16:53:31