Carrot, a Solana-based DeFi yield protocol, introduced its everlasting shutdown on April 30, 2026, after dropping roughly $8 million in complete worth locked, roughly half its TVL – to the fallout from the April 1 Drift Protocol exploit that drained an estimated $285 million from considered one of Solana’s largest perpetual futures platforms.
Carrot was circuitously hacked. It was taken down by a protocol it depended o, and that distinction is what makes this story greater than a routine exploit abstract.
Customers have till Could 14, 2026, to voluntarily withdraw funds from Carrot’s three core merchandise. After that deadline, the crew will start force-deleveraging all remaining positions to 1x leverage, releasing liquidity for last CRT stablecoin redemptions.
Carrot’s official account on X confirmed the choice plainly: “Carrot is shutting down. That is definitely not the result we wished, however the scenario with the Drift exploit has confirmed to be catastrophic for our continued operations.”
A snapshot of CRT token holdings was taken at 20:00 UTC on April 1, the precise second of the Drift exploit, to protect proportional claims for any future Drift restoration distributions paid through IOU token.
1/ Carrot is shutting down
That is definitely not the result we wished, however the scenario with the Drift exploit, has confirmed to be catastrophic for our continued operations.
— Carrot (@DeFiCarrot) April 30, 2026
The element most headlines are lacking is that Carrot by no means had a vulnerability in its personal code. Its Enhance and Turbo merchandise routed consumer funds by Drift-integrated vaults, which means Drift’s safety was additionally Carrot’s safety, whether or not Carrot’s customers knew that or not.
DISCOVER: The Next 1000x Crypto Gem Before It Lists on Binance
How Did the Drift Protocol Exploit Really Work?
The Drift exploit, which the Drift Protocol confirmed occurred at roughly 20:00 UTC on April 1, used what investigators have described as a novel sturdy nonce exploit, a way that manipulates how Solana handles pre-authorized transaction signing to compromise administrative controls.
Attackers, suspected to have ties to North Korean state-sponsored teams, spent roughly three weeks getting ready the assault earlier than executing it. Over 50% of Drift’s TVL was drained in minutes, triggering an instantaneous suspension of deposits and withdrawals throughout the platform.
Carrot held vital publicity by Drift-integrated vaults and liquidity positions. Shortly after the exploit, the crew paused all minting and redemption capabilities whereas assessing the injury.
By mid-April, Carrot’s CRT web asset worth had been adjusted to roughly $57.52 to $57.58 per token, reflecting each realized and unrealized losses. The Drift hack is now the most important DeFi exploit of 2026 and the second-largest in Solana’s historical past – an information level that issues for anybody evaluating the health of the broader Solana ecosystem proper now.
Carrot operated for greater than two years earlier than this shutdown, constructing what it described as a “yield working system” for Solana. No administration charges apply through the wind-down interval, and the crew has confirmed that deposited funds stay the authorized property of customers all through the method.
EXPLORE: Best Crypto Presales to Watch
The submit Solana Yield Protocol Carrot Shuts Down After $8M Exploit appeared first on 99Bitcoins.
