0xGene|Apr 01, 2026 23:19
Drift really went off the rails this time.
Based on the on-chain timeline, the attack started around 00:15 Beijing time. It took over an hour before the community began issuing large-scale warnings on X, and Drift’s official response didn’t come until 02:10. The crazy part? This was a $270M-level attack.
Here’s the conclusion: This looks more like a social engineering/high-privilege signer being specifically compromised, possibly with internal assistance, rather than a vulnerability in the protocol’s contract logic itself.
The attacker gained access to the critical Primary Runtime Admin permission. This permission was originally controlled by a 2/5 Squads multisig. The attacker directly exploited two legitimate signers (6UJ...924, 39Jy...Aq8) to initiate and complete a fully legitimate multisig transaction, transferring the Primary Runtime Admin permission to their own EOA: H7Pi...7ZgL.
From there, the path was straightforward:
First, seize control. Then, modify market parameters. Finally, turn the protocol into a cash machine.
What’s even more bizarre is that the admin path itself showed clear anomalies:
- 9 days ago, the attacker created a durable nonce for the Drift admin-related path.
- 7 days ago, Drift admin created a new multisig (5 signers, 4 of which were brand-new, and 1 was an old address—this old address was “used” again by the attacker during the second attack). For a protocol that’s been live for years, this is already a red flag.
- 2 days ago, the attacker created another durable nonce for a second Drift admin path.
This incident just highlights a painful truth once again: The real vulnerabilities in many DeFi protocols aren’t in the contract logic but in the high-privilege control mechanisms. To put it bluntly—are these administrators really trustworthy?
#DeFi #Crypto #Security #Drift
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink