This hack wasn't a technical failure but a highly sophisticated social engineering attack.

The attackers managed to get multisig members to sign malicious transactions, took control of the protocol, listed a fake token as collateral, and drained $285M in minutes.

The lesson: in DeFi, security no longer relies solely on code but on the human validation of each signature.

How the attack was executed (step by step)

1. -Preparation (weeks or months in advance)

The attackers created fake identities and gained the team's trust.

There was even real-world contact (not just online).

At the same time:

They created a fake token called CarbonVote (CVT)

They simulated price using wash trading

Result: it looked like a legitimate asset

2. - Signature manipulation (the critical point)

They deceived multisig members into signing “normal” transactions

But those signatures had hidden authorizations

- This gave them administrative control of the protocol

3. - Final attack (April 1)

Once they had control:

They listed the fake token (CVT) as valid collateral

They deposited hundreds of millions into that fake token

The system accepted it as if it were real money

Then:

They executed 31 massive withdrawals within minutes

They removed real assets from the protocol

4. - Money laundering

They converted the funds quickly

They moved them from Solana to Ethereum

They made recovery difficult