This hack wasn't a technical failure but a highly sophisticated social engineering attack.
The attackers managed to get multisig members to sign malicious transactions, took control of the protocol, listed a fake token as collateral, and drained $285M in minutes.
The lesson: in DeFi, security no longer relies solely on code but on the human validation of each signature.
How the attack was executed (step by step)
1. -Preparation (weeks or months in advance)
The attackers created fake identities and gained the team's trust.
There was even real-world contact (not just online).
At the same time:
They created a fake token called CarbonVote (CVT)
They simulated price using wash trading
Result: it looked like a legitimate asset
2. - Signature manipulation (the critical point)
They deceived multisig members into signing “normal” transactions
But those signatures had hidden authorizations
- This gave them administrative control of the protocol
3. - Final attack (April 1)
Once they had control:
They listed the fake token (CVT) as valid collateral
They deposited hundreds of millions into that fake token
The system accepted it as if it were real money
Then:
They executed 31 massive withdrawals within minutes
They removed real assets from the protocol
4. - Money laundering
They converted the funds quickly
They moved them from Solana to Ethereum
They made recovery difficult
