0xGene
0xGene|Apr 01, 2026 23:19
Drift really went off the rails this time. Based on the on-chain timeline, the attack started around 00:15 Beijing time. It took over an hour before the community began issuing large-scale warnings on X, and Drift’s official response didn’t come until 02:10. The crazy part? This was a $270M-level attack. Here’s the conclusion: This looks more like a social engineering/high-privilege signer being specifically compromised, possibly with internal assistance, rather than a vulnerability in the protocol’s contract logic itself. The attacker gained access to the critical Primary Runtime Admin permission. This permission was originally controlled by a 2/5 Squads multisig. The attacker directly exploited two legitimate signers (6UJ...924, 39Jy...Aq8) to initiate and complete a fully legitimate multisig transaction, transferring the Primary Runtime Admin permission to their own EOA: H7Pi...7ZgL. From there, the path was straightforward: First, seize control. Then, modify market parameters. Finally, turn the protocol into a cash machine. What’s even more bizarre is that the admin path itself showed clear anomalies: - 9 days ago, the attacker created a durable nonce for the Drift admin-related path. - 7 days ago, Drift admin created a new multisig (5 signers, 4 of which were brand-new, and 1 was an old address—this old address was “used” again by the attacker during the second attack). For a protocol that’s been live for years, this is already a red flag. - 2 days ago, the attacker created another durable nonce for a second Drift admin path. This incident just highlights a painful truth once again: The real vulnerabilities in many DeFi protocols aren’t in the contract logic but in the high-privilege control mechanisms. To put it bluntly—are these administrators really trustworthy? #DeFi #Crypto #Security #Drift
+6
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads