avatar
DEGEN - INSIGHTS
Follow
Posts
avatar
DEGEN - INSIGHTS
Drift Protocol Hack: $285 Million Vanishes in Minutes – A Painful Lesson in Multisig Security Hacker attack methods • The attacker used social engineering to trick members into signing multisigs into pre-signing several transactions (March 23). • They saved this signature and activated it en masse on April 1st, gaining administrative control of the protocol. • After gaining admin privileges, the hacker immediately created a worthless Token on the drift exchange. • Disable the withdrawal security mechanism. • Manipulating the value of collateral assets to withdraw large amounts of real money (mainly JLP, stablecoins, SOL...). ➡️The entire process took only about 12 minutes, with Drift's coffers dropping from over $300 million to approximately $41 million. Main cause: • Drift uses a multisig (Multisignature) system with a low threshold (2/5) and no timelock. Consequence: • The DRIFT Token has dropped by over 40%. • The TVL of the protocol has decreased significantly. • Drift has temporarily suspended deposits/withdrawals, cooperating with security companies to investigate and attempt to track down the stolen funds (some of which have been converted into ETH). • More than 11 protocols are affected. • Hackers laundered money via backpacks, so this project also came under fire. In addition, according to our research: The co-founder of Drift Labs was once honored by Forbes in 2025 (Whoever Forbes honors in the future will face major scandals, be accused of fraud, defrauding investors, or even go to jail).
DRIFT
4.03%
loading indicator
Loading..