The Drift Protocol attack was an unconventional hack that leveraged a legitimate Solana feature called 'durable nonces' to bypass the protocol's multisig security measures. This feature, designed for convenience, allows transactions to remain valid indefinitely, creating a potential vulnerability.
The attacker exploited this by obtaining pre-approved transactions from two multisig members, which were then executed weeks later, resulting in the theft of over $270 million. The attack did not involve a bug in Drift's code but rather manipulated the 'durable nonces' feature to trick the security council into pre-approving transactions. Onchain researchers tracked the stolen funds in real-time, which were transferred to various wallets and eventually bridged to Ethereum addresses. The primary drainer wallet was funded eight days before the attack, and the stolen funds were laundered using Tornado Cash.
The incident highlights the importance of operational security and the potential risks associated with social engineering attacks in the DeFi space. The Drift Protocol has been frozen, and the compromised wallet has been removed from the multisig. An investigation is underway to determine how two separate multisig members approved transactions they did not understand, and whether any tooling or interface changes could have flagged durable nonce transactions as requiring additional scrutiny.