Drift Protocol secures nearly $150M recovery fund with Tether, shifts to USDT
Drift Protocol unveils a user recovery plan after a $285M exploit. It secures up to $150M in support with Tether and will relaunch with USDT at the center.
Headline: Drift, Tether line up up to $150M for user recovery; DEX relaunches on Solana with USDT after $285M exploit
Drift calls it a “structured recovery plan” backed by nearly $150M, combining a credit line, grants, and market‑maker loans. The team shared the plan in an announcement; Tether confirmed its role in a separate statement.
Key funding components:
- $100M revenue‑linked credit line from partners
- Ecosystem grant to the recovery pool for users
- Loans to market makers to seed liquidity at relaunch
A dedicated user recovery pool will be financed by exchange revenue and the committed capital. Any funds clawed back will also go to the pool per Drift.
Drift will issue a new, transferable recovery token. It is separate from the DRIFT governance token and represents a claim on the pool for impacted users.
Security will be hardened before relaunch. Every component goes through independent audits by OtterSec and Asymmetric Research. A new community‑governed multisig will manage core assets, with signers on dedicated devices and out‑of‑band transaction verification per the team. The goal is to prevent similar attacks.
The April 1 exploit drained about $285M across multiple assets, the largest crypto hack of 2026 so far according to NewsBTC.
Relaunch will prioritize USDT settlement. Tether proposed a USDT support facility for designated market makers to ensure deep liquidity on day one per Tether.
This marks a shift from USDC. Circle did not freeze the stolen USDC during the attack, drawing criticism; Circle later said it acts when the law requires and not unilaterally as reported. On‑chain, the exploiter swapped $270.9M into USDC, bridged to Ethereum via CCTP’s TokenMessengerMinterV2, and bought 129,000 ETH, spreading funds across wallets per NewsBTC. ZachXBT publicly criticized Circle’s inaction on X.
Elliptic linked the exploit to DPRK‑associated actors based on multiple indicators in its analysis. Drift said the breach followed a six‑month operation to infiltrate its inner circle and compromise devices per its report.
“First step toward making users whole over time,” Drift wrote, as it moves to rebuild and relaunch the protocol.








