Drift Protocol: No evidence indicates that the mnemonic phrase was stolen; the attacker gained access through unauthorized transaction approvals.

robot
Abstract generation in progress

Deep Tide TechFlow message. On April 02, according to the official disclosure from Drift Protocol (@DriftProtocol), on April 2, a malicious attacker rapidly took over Drift Protocol’s Security Committee management privileges through a new attack method involving durable nonces. The attack was prepared over several weeks and executed in phases; the attacker delayed execution through pre-signed transactions and, using social engineering or transaction misdirection, obtained approval from a multisig wallet (2/5), ultimately completing a malicious transfer of protocol-level privileges.

The Drift team stated that this incident was not caused by a smart contract vulnerability or a leaked seed phrase. The affected scope includes lending deposits, insurance inventory deposits, and trading funds, but DSOL that was not deposited into Drift (including assets staked to Drift validators) and insurance fund assets are not affected.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments