The Drift Protocol attack was unprecedented, as it didn't involve traditional hacking methods such as exploiting code vulnerabilities, flash loan attacks, or oracle manipulation. Instead, the attacker leveraged a legitimate Solana feature known as 'durable nonces' to pre-sign administrative transfers, which were executed weeks later, bypassing the protocol's multisig security measures. This feature allows transactions to remain valid indefinitely, creating a potential security risk if not properly monitored. The attacker obtained signatures from two members of Drift's Security Council, which were then used to execute malicious transactions, resulting in the theft of over $270 million in various tokens.
The stolen funds were transferred to intermediary wallets and eventually bridged to Ethereum addresses via Wormhole, with some funds being laundered through Tornado Cash. The attack highlights the importance of operational security and the need for improved tooling and interfaces to prevent such exploits. The incident is reminiscent of recent social engineering attempts and underscores the increasing trend of attackers targeting the human layer rather than code vulnerabilities.