The Drift Protocol attack was a result of an attacker leveraging Solana's 'durable nonces' feature to pre-sign administrative transfers, which were then executed weeks later, bypassing the protocol's security measures. This feature, designed for convenience, allows transactions to remain valid indefinitely, creating a vulnerability. The attacker obtained signatures from two council members, which were then used to execute malicious transactions, resulting in the theft of over $270 million in various tokens. The attack did not involve a code vulnerability but rather a social engineering tactic that exploited the human layer around the multisig.
The stolen funds were transferred to Ethereum addresses via a cross-chain bridge and mixed using Tornado Cash. The incident highlights the importance of operational security and the need for protocols to re-examine their multisig approval processes.