Key Points
- Carrot DeFi protocol announces permanent closure due to financial damage from the Drift security breach.
- Users face a May 14 deadline to retrieve their remaining assets from the platform.
- Platform’s total value locked plummeted from $28 million to $1.99 million following the attack.
- Attackers compromised Drift through social engineering, obtaining administrative credentials and extracting over half its locked value.
- Multiple integrated platforms experienced significant losses due to connections with Drift’s protocol infrastructure.
The Solana-based DeFi yield protocol Carrot has announced its complete shutdown after sustaining severe losses connected to the Drift security breach. Platform administrators have established May 14 as the final date for users to retrieve their assets. This closure comes after a dramatic decline in locked assets following the April 1 security incident.
Carrot Protocol Announces Permanent Closure After Drift Breach
Carrot revealed its shutdown decision via an official X platform announcement, pointing to financial devastation caused by the Drift security incident. Platform administrators characterized the event as having “catastrophic” consequences and determined that continuing operations was unfeasible. The team emphasized that all users must complete asset withdrawals before the established May 14 cutoff.
According to the platform’s statement, “Your deposited funds are still yours, but all leverage will be reduced to zero.” The announcement clarified that the deleveraging process will release liquidity for CRT token redemption. Officials confirmed their commitment to supporting ongoing recovery initiatives related to Drift.
Carrot’s business model depended heavily on Drift’s infrastructure for yield generation, creating significant vulnerability to the exploit. Following the breach, the platform witnessed its total value locked collapse from $28 million to $1.99 million. Data from DefiLlama indicates this represents approximately 93% loss in locked capital.
Security Breach at Drift Creates Ripple Effect Across DeFi Ecosystem
The April 1 Drift security incident stands as the second-largest cryptocurrency attack recorded in 2026. Malicious actors employed extended social engineering tactics spanning several months to obtain administrative privileges. Following successful infiltration, they extracted more than half of Drift’s total locked value.
The breach created widespread consequences for numerous connected projects, including Gauntlet, PrimeFi, and Elemental DeFi. These platforms encountered severe liquidity challenges stemming from their integrated connections with Drift’s protocol. Carrot emerged as among the first platforms to announce complete shutdown as a result of this exposure.
Carrot officials confirmed their participation in distributing any recovered assets when they become accessible. The development team indicated they will maintain coordination with involved stakeholders throughout the recovery timeline. All leverage across the platform’s products will be eliminated during this transition phase.
April 2026 Sees Massive Spike in Cryptocurrency Theft
According to DefiLlama tracking data, April witnessed approximately $630 million in stolen cryptocurrency across 25 separate security incidents. This monthly total represents the highest recorded loss since February 2025, which saw $1.47 billion in compromised assets.
The $293 million breach targeting liquid staking protocol Kelp currently holds the position as 2026’s largest attack. The Drift exploit, with $285 million in losses, ranks as the second-largest. These two incidents combined represent more than 90% of April’s aggregate losses.
Carrot’s closure demonstrates the cascading consequences of interconnected DeFi infrastructure during major security events. The platform’s deep integration with Drift created vulnerability to swift liquidity depletion. The May 14 withdrawal deadline remains active for all platform participants.





