Wu said that Drift Protocol issued a response stating that this incident was caused by a malicious actor exploiting a new type of attack involving durable nonce to gain unauthorized access and quickly take over the management authority of the Drift security committee. The preparation period for this attack is long and complex, and it is suspected that it was carried out using pre-signed transactions through durable nonce accounts to achieve delayed execution, ultimately resulting in approximately $280 million in funds being withdrawn from the protocol. Drift stated that preliminary investigations indicate that the cause of the incident is not due to any vulnerabilities in its program or smart contracts, and there is no evidence that the mnemonic was stolen; the attacker may have obtained access through unauthorized or forged transaction approvals, or it may involve social engineering.
This incident affects borrowing, bank deposits, and trading funds; DSOL not deposited in Drift (including assets staked to Drift validators) remains unaffected, and the insurance fund assets are also unaffected and are being withdrawn to enhance protection. As a precautionary measure, Drift has frozen the remaining protocol functions and updated the multi-signature to remove the compromised wallet.
