
DeFi Protocol Carrot Shuts Down Following $285M Drift Exploit
Carrot, a Solana-based decentralized finance yield protocol, has announced its permanent shutdown due to the financial impact of the $285 million Drift Protocol exploit in early April. The protocol's total value locked (TVL) has collapsed by 93% in a month, from $28 million to $1.99 million, leaving it unable to continue operating.
The Drift Protocol exploit, which occurred on April 1, was a highly coordinated attack involving months of social engineering by a group of hackers who gained admin control and drained more than half of the protocol's TVL. The contagion spread to several affiliated projects, including Carrot, which was integrated with Drift's infrastructure and used its pools to generate yield for its users.
Carrot has set a May 14 deadline for users to withdraw remaining funds, after which it will begin to deleverage the system and distribute assets once they become available. The protocol's shutdown is a significant consequence of the Drift exploit, which is the second-largest in 2026. According to data from DefiLlama, nearly $630 million worth of digital assets were stolen in April across 25 incidents, making it the month with the largest losses since February 2025.
The Drift hack, along with the $293 million hack on liquid staking protocol Kelp, accounts for more than 90% of all crypto stolen in April. The incident highlights the need for DeFi protocols to prioritize security and take proactive measures to prevent such exploits. Carrot's shutdown serves as a reminder of the potential risks and consequences of investing in DeFi protocols, and the importance of conducting thorough research and due diligence before investing.