Drift: "Hack Exploiting Delayed Execution Occurred… Tracking and Freezing Stolen Assets Underway"

Source
YM Lee

Summary

  • Drift said the attack combined a durable nonce, a delayed-execution mechanism, and stolen multisig approvals, resulting in the loss of administrator control.
  • It said the incident was not due to a smart contract bug, a program vulnerability, or seed phrase compromise, and that the key was a delayed-execution setup leveraging pre-approved transactions.
  • The attack impacted lending, deposit, and trading funds, and Drift said it is working with security firms, exchanges, bridges, and law enforcement to track and freeze the stolen assets.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo=Drift
Photo=Drift

Solana-based DeFi protocol Drift has issued an official statement on the cause of the latest hacking incident.

According to Drift’s official announcement on the 2nd (local time), the attack was confirmed to have been carried out by combining a delayed-execution mechanism using a “durable nonce” with the theft of multisig approvals.

The attacker reportedly pre-signed transactions via a durable nonce account and delayed their execution, then executed them within a short window to seize administrator privileges. Drift said, “The attacker obtained approvals from 2 of the 5 multisig signers and executed an admin transfer,” adding that “this allowed them to take control of protocol-level permissions.”

Drift also denied the commonly raised possibility of a technical vulnerability. “This incident was not caused by a smart contract bug or a program vulnerability,” the team said. “There is also no evidence that the seed phrase was compromised. The core of the attack is the delayed-execution structure leveraging pre-approved transactions.”

The attack is believed to have been a sophisticated operation prepared over several weeks, with multisig approvals likely obtained through social engineering or mistaken transaction approvals.

The damage affected major functions across the protocol, including lending, deposits, and trading funds. However, DSOL and insurance fund assets not deposited in Drift were excluded from the affected assets.

Drift is currently working with security firms, exchanges, bridges, and law enforcement agencies to track and freeze the stolen assets. Drift said it is “cooperating with various organizations to track and freeze the stolen assets.”

YM Lee

YM Lee

20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE
hot_people_entry_banner in news detail bottom articleshot_people_entry_banner in news detail mobile bottom articles
What did you think of the article you just read?




PiCK News

A pledge by President Lee—but Bitcoin spot ETFs remain in limbo as the framework act stalls

1 hours ago
A pledge by President Lee—but Bitcoin spot ETFs remain in limbo as the framework act stalls

U.S. spot Bitcoin ETFs see $174 million in net outflows…institutional flow volatility rises

4 hours ago
U.S. spot Bitcoin ETFs see $174 million in net outflows…institutional flow volatility rises

Trump: "We have all the cards"…In address to the nation, underscores both negotiations and offensive action

7 hours ago
Trump: "We have all the cards"…In address to the nation, underscores both negotiations and offensive action

Trump: ‘We will send Iran back to the Stone Age’… signals a major offensive over the next 2–3 weeks

7 hours ago
Trump: ‘We will send Iran back to the Stone Age’… signals a major offensive over the next 2–3 weeks

Iran Demands Transit Fees for Passage Through the Strait of Hormuz…Using Stablecoins and Yuan Payments

8 hours ago
Iran Demands Transit Fees for Passage Through the Strait of Hormuz…Using Stablecoins and Yuan Payments

Trending News