Published 5 months ago • loading... • Updated 5 months ago
Here is how Drift attackers drained more than $270 million using a Solana feature designed for convenience
Attackers used durable nonces and pre-signed approvals to seize admin control, drain more than $270 million, and freeze the protocol, researchers said.
On April 1, an attacker drained $285 million from Drift Protocol, a Solana-based perpetual futures exchange, marking the second-largest exploit in the network's history and highlighting security risks beyond smart contracts.
The exploit did not involve smart contract bugs; instead, attackers misused a legitimate Solana feature called 'durable nonces' to trick two of five Security Council multisig members into pre-approving malicious transactions.
Using administrative access, the attacker created a fake token called CarbonVote Token to manipulate price oracles, enabling them to drain over $250 million from Drift's shared liquidity pool.
Onchain investigator ZachXBT criticized Circle for failing to freeze stolen USDC as the attacker bridged over $230 million to Ethereum via Circle's Cross-Chain Transfer Protocol during U.S. business hours.
Security experts warn that operational failures, rather than code vulnerabilities, are becoming the primary method for DeFi exploits, as Solana's SOL token fell 5.5% to around $78 following the incident.