DIP-10: Treatment of Remaining Asset in Borrow Lend

Abstract

DIP-10 establishes the framework for assisting with recovering user balances affected by the April 1, 2026 incident. The proposal authorises Drift Foundation to convert all remaining spot assets in the borrow/lend pool to stablecoins, which will form the reserve for the recovery pool at launch. It also defines the methodology for how user positions and balances are calculated for settlement purposes.

Context

On April 1, 2026, Drift Protocol experienced a security incident that resulted in the program being paused at 18:31:47 UTC. A full incident summary and list of affected spot assets can be found in the Incident Recovery Update.

Following the incident, the protocol holds a set of residual spot assets across the borrow/lend pool. This proposal defines the process for converting those assets and the principles governing how user balances will be determined for recovery purposes.

Reasoning

Why convert spot assets to stablecoins?

Converting residual spot assets to USDT provides a clean, denominated basis for a recovery pool. A USDT reserve eliminates price volatility exposure between now and recovery launch, ensuring users receive a settlement backed by a predictable notional value rather than a basket of assets subject to market fluctuation.

The Foundation will explore all available conversion avenues such as spot trading, OTC desks, and on-chain aggregators, the avenue chosen will be at the Foundation’s sole discretion, in each case will be based on the best available liquidity and operational feasibility at the time of execution.

Why are spot assets not returned directly to depositors?

All borrow/lend markets share a single liquidity pool. Any given subaccount may have had an outstanding borrow position against their deposited assets. Returning deposits to lenders before those borrows are settled would remove liquidity that other accounts depend on, permanently breaking the pool’s accounting integrity. A unified conversion and settlement process is the only approach that preserves fairness across all affected parties.


Proposal

1. Spot Asset Conversion

All remaining spot assets listed in the Incident Recovery Update held within the borrow/lend pool will be converted to USDT by the Foundation. Conversion avenues may include but are not limited to spot trading, OTC desks, and on-chain aggregators. The avenue selected for each asset will be based on the best combination of liquidity depth and operational efficiency available at the time. The final converted notional value will constitute the initial backing reserve for the recovery pool at launch.

2. Interest Accrual

Interest accrual is cut off at the program pause timestamp, consistent with the spot balance snapshot. All interest accrued within the impacted window has been incorporated into the snapshot calculation. Users will not be required to pay any outstanding interest upon protocol restart.


Considerations

If passed, the Foundation and Security Council should retain discretion to implement this proposal, including in relation to the timing and sequencing of asset conversions to maximise notional recovery and avoid unnecessary market impact. If material adjustments are required for conversion methodology or settlement parameters, a transparency statement will be issued on Discourse. This proposal is narrowly scoped to the conversion and settlement mechanics of the remaining assets in the borrow/lend pool.

1 Like

For Drift to have any hope of continuing in the future the insurance fund must be returned to the original owners.

The whole concept of a DAO vote on taking the funds for the recovery fund is effectively an attempt at money laundering.

Anything other that a full return of funds would constitute wire fraud.

4 Likes

Proposal can be better by adding one more choice, e.g. launch a trading intranet version, any original digital is kept inside the protocol that can be utilized internally, while enabling original amount to access drift trading system, swing trading profit can be withdraw anytime.

I understand the rationale behind converting the remaining spot assets into USDT and establishing a recovery reserve pool.

However, I believe the current discussion is focused mainly on how to redistribute the remaining assets, rather than further addressing how the protocol itself intends to meaningfully support users’ long-term recovery.

For many affected users, the current remaining asset value represents only a small fraction of their original balances. Converting existing assets into stablecoins may help stabilize accounting and settlement mechanisms, but by itself, it does not materially improve recovery outcomes for users.

I believe the discussion should also urgently include clearer recovery mechanisms, such as:

  • Whether a portion of the protocol’s past accumulated revenue should also be allocated into the recovery pool

  • What percentage of future protocol revenue will continue to be directed toward the recovery pool

  • The scale of support from ecosystem partners — currently, including Tether and strategic partners, there has not yet been a clear indication of how much capital or what percentage will be contributed to the recovery pool

  • Whether recovery incentives tied to the protocol’s long-term growth can be introduced, allowing affected users to participate in future value creation

From a user perspective, recovery is not only about immediate settlement mechanics, but more importantly whether the protocol is willing to share responsibility with affected users in rebuilding the lost value.

I believe that a clearer and longer-term recovery commitment would also help strengthen community trust, user retention, and overall confidence in the protocol relaunch.

2 Likes

The “everything was pooled” point is valid, but it doesn’t justify pretending there is no structure inside that pool. We already did per‑address, per‑product accounting to compute verified losses; the same data shows that some users ended with net, un‑borrowed spot exposure and some didn’t. Choosing to convert 100% of the residual assets to USDT and drop them into a common reserve is therefore not an accounting necessity, it’s a policy decision to favour simplicity over distributional fairness. If we’re serious about “doing it right this time”, we should at least consider a carve‑out for clearly identifiable spot‑only exposure.

I think it helps to put this in personal terms: if any of us after an incident and saw that our account still had a residual coin balance that was never actually lent out or stolen, we’d expect that fact to matter in how losses are allocated. The current DIP‑10 approach effectively says those balances are irrelevant and should be treated exactly the same as assets that were drained, purely for simplicity. That may be neat from an accounting perspective, but it’s hard to square with a basic sense of fairness.

I encourage governance to vote NO to this proposal in its current form, after all we haven’t even seen the absolutely critical proposed contributions to the Recovery Fund from Drift or Tether. There is no need to act in haste here; most users already accept, and in many cases actively seek, market exposure.

1 Like

I’m affected by this with spot-only exposure, and some of my tokens weren’t even in the drained set. Still, I don’t really see how account-based fairness would hold up here. Deposits into a shared lending pool aren’t sitting in a vault with your name on them, and which tickers the attacker grabbed came down to exit liquidity, not anything about the depositor. Freezing everything in USDT seems like a clean way to keep claims aligned.

What I don’t get is the weird sequencing is. I get why the exact numbers from Foundation, Tether, and partners aren’t locked in yet since a lot of that is revenue-linked and hard to commit to upfront. But at least the structure of how those contributions fit into the recovery should be on the table before we authorize converting the residuals. Right now it feels bad that depositors are first in line to eat the loss without any details on the parts of the recovery plan.

1 Like

Those Drift users that are involved in assets that were not drained should not have what is left of their money taken away from them to socialise losses, just because it is easier to liquidate everything into one stablecoin pot.

The amount that is left now after the attack is far away from making good what was exploited, it is not Drifts right to take what little is left from their owners just to get the recovery pot started.

if we start with a bad deal users will not want to engage with the protocol after relaunch to support filing the recovery fund via platform revenue. The fairest approach would be to start the recovery fund from zero with the token share mechanics, build it up with the relaunch and support from Tether and others and make a clearer recovery plan. There is still a very long and difficult path to recovery.

Balances of those not/less affected have what is left of their hard earned money set aside for reclaim later. Any verifiable losses they have on their account gives them claim on the recovery pot with appropriately proportioned tokens to burn.

2 Likes

Let’s make sure nobody is getting any bonus from contributions.

Doesn’t this also mean we will need to dump 8.74M of Drift tokens? How would that impact the governance?

Return spot assets for unaffected users. I personally lost 400k but it is not their responsibility. I see zero accountability from Drift team and it seems all users getting frustrated. Join https://x.com/driftvictims?s=21&t=9adrZcZ_Pm6pUijsI53wVA

3 Likes

This is not legal for IF funds. Depositors in the Insurance Fund (IF) placed their funds under distinct legal terms that do not include any clause allowing the protocol to redirect, seize, or repurpose their assets. There is no mechanism in the existing agreements that permits such a change. The seizing was a temporary security measure but you can’t hold them forever as it is (and never has) been yours. If the team proceeds with any vote to alter the Insurance Fund against its legal terms and without the explicit consent of depositors, it will:

  • Destroy what remains of the team’s credibility
  • Expose the team to serious legal liability for misappropriation of funds

This shouldn’t even be discussed, this should not be hidden behind a vague DAO vote where IF stakers doesn’t have a say. Legal terms apply here and Drift position was clear from the beginning: IF were untouched, and were going to be returned to the original stakers. The feedback from the community on this matter is loud and clear: respect your IF users or you’ll face a coordinated class lawsuit and an irreversible loss of trust.

1 Like

I don’t think the proposal has nothing to do with the insurance fund. It is scoped explicitly to the handling of the residue borrow/lend pool.

I hope you are right. All legal hell is going to break out if they try to steal the IF

1 Like

I fully expect IF depositors to be able to withdraw their funds at some point. As previously stated by Drift:

Insurance Fund Status

The Insurance Fund is designed to maintain solvency in cases of trading-related bankruptcies (e.g. liquidations or borrower defaults where collateral is insufficient). It is funded by stakers who take on this specific risk in exchange for yield. The Insurance Fund is unaffected and all Insurance Fund depositors’ assets remain intact and will be available to depositors upon protocol relaunch.

However, USDT is quite restricted in my region so this is somewhat frustrating if these assets were also being converted.

2 Likes

I support the proposal. But I didn’t have any assets listed in the residual pool, so am obviously biased.

every day we don’t relaunch means less revenue generated, less momentum built and less trust re-earned. I have a mixed bag of tokens that hasn’t been drained and USDC. As much as I would like to see a perfectly fair proposal, time is just not on our side. Let’s get this over it so we can focus on the relaunch.

2 Likes

Governance is clearly aware of the considerable criticism of the proposed treatment of remaining assets on the platform. A lack of appreciation for detail and a desire to simplify things and take short‑cuts is exactly what led to the op‑sec disaster in the first place. It is frustrating, to say the least, to have partially survived the initial attack only to then face a second wipe‑out via governance decisions that repeat the same “simplify at all costs” mindset on the economic side.

Tether’s CEO talks a lot about fairness, financial inclusion, and the idea that no one should be able to arbitrarily block or interfere with people’s money. I had hoped that partnership would help tighten Drift’s culture around careful risk and user treatment, but as it stands the attempt at garnering goodwill is going stale. I’m a big supporter of Tether’s products (notably XAUt), yet the association with Drift and its treatment of the v2 user base is starting to call that into question.

I would appeal to Tether to use its influence to push for a fairer outcome: rather than effectively burning the v2 cohort entirely in order to present a cleaner story for v3, help Drift governance find a path that salvages at least some goodwill for the users whose money is now being used to “seed” that future.

1 Like

i’d actually benefit from a carve-out. part of my position was a low liq pump token the attacker didnt even touch, and i took my real loss on USDC. so if “return clearly identifiable spot-only holdings” became policy i’d be on the winning side of it. still dont think it holds up. Take a with a grain of salt since it is based on my understanding of how things work in the doc and code when I desposited.

the borrow/lend pool is one balance sheet since it is cross-collateralized and the exploit blew a hole in it. doesnt matter that the hole is on the USDC side and my pump token is sitting there untouched, the pool as a whole is short now, claims exceed assets, and theres still borrows drawing against that same shared balance sheet. “my token wasn’t taken” and “my token isn’t affected” are two different things. first one is true. second one isn’t.

analogy: farmers store different grains in one shared barn, and the barn lends grain out against the whole stock. Thief takes the barley. Your wheat’s still in the corner, but the barn was operating as one pool, it’s now short, and your receipt was always a claim on the barn, not on your sacks.

a carve-out basically lets the attacker’s path decide who eats the loss. the pooled haircut treats two identical depositors the same.

i’d take the carve-out if it passed lol. just cant honestly argue the current proposal is the unfair one.

I agree with you that the barn is one balance sheet and that my receipt was always a claim on the pool, not on a specific sack – so “my token wasn’t taken” and “my token can’t be touched” are different things. Where I disagree is with the leap from “one barn” to “therefore we must socialise 100% of all residual assets into the reserve and treat every path of losses identically.”

In your grain example, if the barn is insolvent you still have choices about how to allocate the shortfall: you can give everyone a uniform percentage claim on the barn, or you can recognise that some farmers clearly still have grain in the corner and structure the workout so they don’t take the same effective haircut as someone whose sacks are completely gone. Both approaches ‘respect’ the pooled nature of the barn; they just draw the fairness line in different places.

The current plan chooses the strongest possible form of socialisation – sweep 100% of the surviving assets into USDT and the reserve – even though the accounting that produced “verified losses” already distinguishes between very different end states for different depositors. It’s a governance choice about distribution, not something forced by the fact that the system was pooled. We should favour fairness over simplicity.

1 Like

Drift appears to be trying to solve one liability by creating another.
The Insurance Fund was first described as unaffected, with depositor assets intact. Now governance is being asked to decide whether those same unaffected, purpose-specific user funds should be redirected into the recovery pool.
Redirecting user-owned IF principal would barely improve recovery math, but it would permanently damage Drift’s credibility. Taking the IF may move recoveries by only a few percentage points, while proving that “unaffected” user funds can still be reclassified after the fact.
It also will not satisfy impacted users waiting on recovery. Anyone considering legal action against Drift is unlikely to stop because IF depositors were also forced to absorb losses.
Instead, Drift would create a second group of directly harmed users by Drift itself: IF depositors whose funds survived the exploit but were later redirected by governance.
That is not recovery. That is socializing an operational failure onto a specific user class that never agreed to insure it.
Return user-owned IF principal. Publish the full IF ownership breakdown. Let governance discuss only protocol-owned IF balances.

2 Likes