Carrot, a Solana-based DeFi yield protocol, introduced its everlasting shutdown on April 30, 2026, after dropping roughly $8 million in complete worth locked, roughly half its TVL – to the fallout from the April 1 Drift Protocol exploit that drained an estimated $285 million from one among Solana’s largest perpetual futures platforms.
Carrot was in a roundabout way hacked. It was taken down by a protocol it depended o, and that distinction is what makes this story greater than a routine exploit abstract.
Customers have till Might 14, 2026, to voluntarily withdraw funds from Carrot’s three core merchandise. After that deadline, the group will start force-deleveraging all remaining positions to 1x leverage, releasing liquidity for closing CRT stablecoin redemptions.
Carrot’s official account on X confirmed the choice plainly: “Carrot is shutting down. That is definitely not the end result we wished, however the scenario with the Drift exploit has confirmed to be catastrophic for our continued operations.”
A snapshot of CRT token holdings was taken at 20:00 UTC on April 1, the precise second of the Drift exploit, to protect proportional claims for any future Drift restoration distributions paid by way of IOU token.
1/ Carrot is shutting down
That is definitely not the end result we wished, however the scenario with the Drift exploit, has confirmed to be catastrophic for our continued operations.
— Carrot (@DeFiCarrot) April 30, 2026
The element most headlines are lacking is that Carrot by no means had a vulnerability in its personal code. Its Increase and Turbo merchandise routed consumer funds by Drift-integrated vaults, which means Drift’s safety was additionally Carrot’s safety, whether or not Carrot’s customers knew that or not.
DISCOVER:Â The Subsequent 1000x Crypto Gem Earlier than It Lists on Binance
How Did the Drift Protocol Exploit Truly Work?
The Drift exploit, which the Drift Protocol confirmed occurred at roughly 20:00 UTC on April 1, used what investigators have described as a novel sturdy nonce exploit, a method that manipulates how Solana handles pre-authorized transaction signing to compromise administrative controls.
Attackers, suspected to have ties to North Korean state-sponsored teams, spent roughly three weeks making ready the assault earlier than executing it. Over 50% of Drift’s TVL was drained in minutes, triggering a direct suspension of deposits and withdrawals throughout the platform.
Carrot held vital publicity by Drift-integrated vaults and liquidity positions. Shortly after the exploit, the group paused all minting and redemption features whereas assessing the harm.
By mid-April, Carrot’s CRT internet asset worth had been adjusted to roughly $57.52 to $57.58 per token, reflecting each realized and unrealized losses. The Drift hack is now the most important DeFi exploit of 2026 and the second-largest in Solana’s historical past – an information level that issues for anybody evaluating the well being of the broader Solana ecosystem proper now.
Carrot operated for greater than two years earlier than this shutdown, constructing what it described as a “yield working system” for Solana. No administration charges apply throughout the wind-down interval, and the group has confirmed that deposited funds stay the authorized property of customers all through the method.
EXPLORE: Greatest Crypto Presales to Watch
The submit Solana Yield Protocol Carrot Shuts Down After $8M Exploit appeared first on 99Bitcoins.







