1/ The core of the vulnerability in Drift Protocol lies in the breach of the multisig governance mechanism. The attacker updated the administrator privileges of the Drift state account and initialized a spot market vault based on a scam token $CVT.

Drift
@DriftProtocol
04-02
We are observing unusual activity on the protocol. We are currently investigating. Please do not deposit funds into the protocol while we investigate. This is not an April Fools joke. Proceed with caution until further notice. We’ll provide additional updates from this account.
2/ The attacker made $CVT valuation extremely high by manipulating the oracle price. Then, by leveraging Drift's cross-margin and exchange functions, a large amount of almost valueless CVTS were deposited and real assets were withdrawn, resulting in losses of about $270M.
Sector:
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content




