The Drift Protocol attack was a unique exploit that did not involve a bug in the code or a traditional hack. Instead, an attacker leveraged a legitimate Solana feature called 'durable nonces' to pre-sign administrative transfers that would be executed at a later time. This feature allows for the creation of indefinitely valid transactions, which can be problematic as they can be executed at any time without the signer's knowledge or consent.

The attacker obtained signatures from two members of Drift's Security Council, which has a multisig system requiring at least two approvals for any action. The signatures were obtained through 'unauthorized or misrepresented transaction approvals,' where the signers likely thought they were approving routine transactions. The attacker then used these pre-signed transactions to drain over $270 million from Drift's vaults. The stolen assets included various tokens such as JPL, USDC, and WBTC, and were transferred to intermediary wallets and eventually to Ethereum addresses via cross-chain bridges.

The attack highlights the dangers of social engineering and operational security failures in DeFi protocols, and raises questions about the security of Solana's durable nonce feature and the need for additional scrutiny of such transactions.