Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Drift’s $230M Hack Looks Like Bybit All Over Again: Ledger CTO

Charles Guillemet says the $230 million Drift Protocol exploit likely involved compromised multisig signers tricked into approving a malicious transaction.

Written By Dhara Chavda
Fact Checked by Divya Mistry
Published 2026-04-02·Updated 5 months ago
Make The Crypto Times preferred on GoogleGoogle
Drift's $230M Hack Looks Like Bybit All Over Again: Ledger CTO

Key Highlights

  • Ledger CTO Charles Guillemet says the $230 million Drift Protocol hack likely resulted from a compromised multisig, where attackers either stole enough private keys or tricked signers into approving a malicious transaction.
  • Guillemet compared the attack pattern directly to the Bybit hack, widely attributed to DPRK-linked actors.
  • He called for an industry-wide security reset, advocating for better detection mechanisms, hardware-backed key management, and clear signing standards.

Charles Guillemet, Chief Technology Officer at hardware wallet manufacturer Ledger, has weighed in on the Drift Protocol exploit, calling it “yet another wake-up call for the industry” and drawing a direct comparison to the $1.4 billion Bybit hack of 2025—widely attributed to North Korea’s Lazarus Group.

Guillemet said the full details of the attack are still unfolding, but based on available evidence, the multisig controlling Drift Protocol was compromised—potentially days or even weeks before the $230 million in funds were actually drained.

“Either the attackers directly stole enough private keys to meet the multisig threshold, or, more likely, they compromised several machines belonging to multisig signers and tricked the operators into approving a malicious transaction,” Guillemet said. “The signers may have believed they were signing a legitimate operation while unknowingly authorizing the drain.”

This attack vector — targeting the human and operational layer rather than the underlying smart contracts — has become the defining pattern of the most devastating crypto exploits in recent years. Guillemet called it “patient, sophisticated supply-chain-level compromise,” explicitly connecting it to the DPRK-linked playbook seen in the Bybit breach.

The Bybit playbook: Human layer, not code

The comparison to Bybit is pointed. In February 2025, attackers — later attributed by the FBI to North Korea’s Lazarus Group — compromised Bybit’s multisig infrastructure by targeting the machines of individual signers.

The signers believed they were approving routine transactions; instead, they authorized transfers that drained approximately $1.4 billion from the exchange’s cold wallet. The attack did not exploit any smart contract bug. It exploited trust, operational process, and the gap between what signers saw on screen and what they actually signed.

Guillemet is now warning that the same blueprint is being repeated.

Drift Protocol’s $230 million exploit follows an identical arc: multisig compromise, compromised signer machines, and malicious transaction approval disguised as a legitimate operation.

On-chain researchers have noted that the attacker’s address was first funded with 1 SOL approximately a week before the exploit, suggesting pre-positioning well ahead of the actual drain.

Three pillars: Detection, Key Management, Clear Signing

Guillemet outlined three concrete steps the industry must adopt:

First, better detection mechanisms at the network and endpoint level to identify compromised environments before they can be weaponized. In both the Bybit and Drift cases, the attacker had access to signer machines for an extended period before executing the drain. Earlier detection of anomalous endpoint behavior could have interrupted the kill chain.

Second, secure key management with proper governance — specifically, hardware-backed signing and operational procedures that assume individual machines can be compromised. Multisig setups that rely on software wallets running on internet-connected machines are fundamentally vulnerable to the type of supply-chain compromise seen here.

Third, and most critical, clear signing ensures that signers always have full, human-readable visibility into what they are actually approving. In both the Bybit and Drift exploits, the attackers’ advantage was that signers could not distinguish a malicious transaction from a legitimate one at the point of approval.

“Security is not just about code audits,” Guillemet said. “It’s about giving operators and users the right information at the right time, so they can make informed decisions about what they sign.”

Drift fallout

The exploit’s impact on Drift Protocol has been severe. The platform’s total value locked (TVL) collapsed from approximately $550 million to under $250 million, according to DeFiLlama data. Drift’s native token, DRIFT, dropped nearly 28%, trading around $0.049—down more than 98% from its November 2024 all-time high of $2.60.

Drift confirmed the attack on X, stating it had suspended deposits and withdrawals and was coordinating with security firms, bridges, and exchanges to contain the incident. The attacker rapidly swapped stolen assets into USDC and bridged them from Solana to Ethereum, with on-chain investigator ZachXBT reporting that over $230 million in USDC was bridged via Circle’s CCTP across 100+ transactions over approximately six hours—with no intervention from Circle, drawing sharp criticism from the crypto community.

Publicly traded Solana treasury firms Forward Industries and DeFi Development Corp confirmed their treasuries were not impacted, while wallet provider Phantom implemented user warnings.

As Guillemet said, “Ultimately, security is not just about code audits. It’s about giving operators and users the right information at the right time.”

The $230 million question for the industry is whether it will treat this as another isolated incident—or as the pattern it clearly is.

Also Read: The First 24 Hours After a Crypto Hack: A Minute-by-Minute Breakdown

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:BybitCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

CFTC Proposes Exemptions to Ease Rules for Crypto Funds
CFTC Proposes Exemptions to Ease Rules for Crypto Funds
Ripple Prime Raises $275M as It Expands U.S. Crypto Business
Ripple Prime Raises $275M as It Expands U.S. Crypto Business
SEC Proposes New Crypto Rules With $75M Offering Exemption 
SEC Proposes New Crypto Rules With $75M Offering Exemption 
Ava Labs Names Charley Cooper President as John Wu Moves to Senior Advisor
Ava Labs Names Charley Cooper President as John Wu Moves to Senior Advisor
a16z Backs SEC Proposal to Rescind Rule 611 for Onchain Markets 
a16z Backs SEC Proposal to Rescind Rule 611 for Onchain Markets 

Find Us on Socials

You may also like

ARK Says Anthropic, OpenAI Revenue Tops $115B as Crypto Markets Price AI Boom

ARK Says Anthropic, OpenAI Revenue Tops $115B as Crypto Markets Price AI Boom

Georgia Man Faces Charges in $165M Crypto Ponzi Scheme

Georgia Man Faces Charges in $165M Crypto Ponzi Scheme

Cathie Wood's ARK Invest Buys Block, Nvidia & Securitize, Sells Shopify & Palantir

Cathie Wood’s ARK Invest Buys Block, Nvidia & Securitize, Sells Shopify & Palantir

Hackers Exploit Apple Screen Sharing Flaw to Mine Monero on Macs

Hackers Exploit Apple Screen Sharing Flaw to Mine Monero on Macs

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information