CoinwyCoinwy
  • Blockchain
  • Crypto
  • Market
  • News
  • Contact
Reading: Drift Says Nonce Attack Drove Exploit as Circle Faces USDC Scrutiny
Share
Font ResizerAa
CoinwyCoinwy
Font ResizerAa
  • Home
  • Crypto
  • Market
  • News
  • Blockchain
  • Contact
Search
  • Categories
    • News
    • Market
    • Crypto
    • Coinbase
    • Mining
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Coinwy > Blog > News > Drift Says Nonce Attack Drove Exploit as Circle Faces USDC Scrutiny
News

Drift Says Nonce Attack Drove Exploit as Circle Faces USDC Scrutiny

Thiago Alvarez
Last updated: April 2, 2026 12:14 pm
Thiago Alvarez
Published: April 2, 2026
Share

Drift said its Drift nonce attack exploit stemmed from a pre-positioned approval scheme using Solana nonce tooling rather than a flaw in its smart contracts, but the episode is also reviving a harder market question: how much intervention traders should expect from centralized stablecoin issuers when stolen funds move into USDC.

Contents
Drift narrowed the cause, but the reported damage still sets the stakesCircle’s documented powers are why the USDC angle drew scrutinyConfidence held in the token, but governance questions widened

Drift narrowed the cause, but the reported damage still sets the stakes

In posts on X, Drift said there was no evidence of compromised seed phrases and no indication that the exploit came from a bug in its programs or smart contracts. The team instead said the attacker relied on unauthorized or misrepresented transaction approvals that had been obtained before execution.

Drift’s follow-up explanation said the attacker used durable nonce accounts, secured 2 of 5 multisig approvals, and then executed a malicious admin transfer. That attribution shifts the focus from code integrity to governance and signing controls, which is a materially different risk profile for users assessing what failed.

$285 million is the size Bloomberg Law said cybersecurity and analytics firms flagged in the incident, and the same report said some of the stolen cryptocurrencies were later converted into USDC.

$285 million
Estimated size of the exploit flagged in reporting about the Drift incident.

Solana’s durable nonce design lets a transaction use a stored nonce instead of a recent blockhash, removing the 150-slot expiry window that normally limits how long a signed transaction stays valid. In plain language, that creates room for offline signing and delayed submission, which lines up with Drift’s account of access being staged ahead of execution.

Circle’s documented powers are why the USDC angle drew scrutiny

Circle’s CCTP materials say USDC moves across chains on a 1:1 burn-and-mint basis and that crosschain transfers are validated by Circle. That operational role helps explain why the issuer became part of the conversation once reporting said part of the stolen assets had been converted into USDC and moved toward Ethereum.

Circle’s USDC Terms also say the company can block certain addresses and may freeze USDC or surrender associated dollars when it receives a legal order from a valid government authority. That is the clearest documented basis for the criticism, even though the reviewed materials did not include an incident-specific Circle statement about the Drift case.

The strongest market defense for Circle is that the USDC price held near $0.9998. Its market cap was about $77.23 billion, while 24-hour volume was roughly $13.45 billion, a sign that traders kept treating the token as liquid infrastructure rather than as a depeg event.

$77.23 billion
CoinGecko market cap snapshot for USDC on April 2, 2026.

Still, one report said critics believed Circle had at least six hours to freeze Drift-linked funds, and the same report said the exploiter may have swapped as much as $270 million into USDC before bridging to Ethereum. Those points remain unconfirmed in the material available here and should be read as reported allegations, not established facts.

Confidence held in the token, but governance questions widened

KEY TAKEAWAY

  • Drift said the exploit was driven by prior approvals and durable nonce accounts, not a smart-contract bug.
  • Circle’s own terms show it has blocklisting and freeze powers under defined conditions, which is why USDC became part of the debate.
  • The verifiable market data point is resilience, with USDC holding near its peg even as questions around intervention intensified.

The bull case rests on Drift’s statement that its programs were not at fault and on the USDC price holding near $0.9998. Those two data points suggest the market treated the episode as an operational-control failure rather than evidence of a hidden stablecoin or smart-contract breakdown.

The bear case is that a reported $285 million exploit linked to prior approvals can still expose weak human processes even if the code path stays intact. That is why governance and compliance questions now sit alongside the technical debate, much like Coinwy’s recent coverage of the Nishad Singh CFTC case and CLARITY Act markup talks.

The same trust trade-off is showing up elsewhere in crypto balance sheets and regulation, including Genius Group’s Bitcoin treasury reshuffle after 171% revenue growth, where market confidence depends on management choices as much as asset prices. In the Drift case, the unresolved question is whether centralized issuer powers described in Circle’s terms should be treated as a last-resort safeguard or as discretion the market cannot reliably count on during a live exploit.

What traders can verify now is narrower than the social debate: Drift described a durable nonce approval attack, Solana’s documentation explains how that design extends transaction validity, and Circle’s legal terms show that freeze powers exist under defined conditions. The next decisive evidence would be an incident-specific Circle statement, a verifiable freeze record, or explorer-linked transaction data showing exactly how the USDC leg unfolded.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Read also :

  • Coinbase CLO Says CLARITY Act Nears Senate Markup as Floor Vote Talk Builds
  • Former FTX Engineer Nishad Singh Fined $3.7M in CFTC Fraud Case
  • Genius Group Sells Bitcoin Treasury After Revenue Jumps 171%
  • Trump Threatens Iran With Strikes in Coming Weeks
  • SpaceX Reportedly Files IPO at $1.75T Valuation
Bitcoin and Ethereum ETFs See Record Inflows and Outflows
Airdrop Crypto Alert – Noomez Presale Launch Includes Bonus Rewards for Early Supporters
China Supports Stablecoin Supervision and Audit Integration
Qubetics, XRP, Artificial Superintelligence Alliance: Best Altcoins to Invest in Now
Tokenised RWAs in focus as BTC Markets seeks ASIC licence

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
ByThiago Alvarez
Thiago Alvarez is a crypto and fintech analyst at Coinwy, covering blockchain payments, DeFi protocols, and digital asset regulation. With a background in financial technology and compliance analysis, Thiago focuses on evaluating the operational viability and regulatory positioning of emerging crypto projects. His work examines token economics, cross-border payment infrastructure, and institutional adoption trends across global markets.
Previous Article Coinbase CLO Says CLARITY Act Nears Senate Markup as Floor Vote Talk Builds

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Popular News
$20 Million HBAR Liquidation as Price Breaks Downtrend
PlanB Criticizes Ethereum on Centralization and Pre-mining
Bitcoin Faces $88K Resistance as Options Expire

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

©2024 Coinwy.com. All Rights Reserved.
  • About Coinwy
  • Editorial Policy
  • Our Team
  • Terms of Service
  • Disclaimer
  • Privacy Policy
  • Contact
Go to mobile version
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?