The Drift Protocol attack was an unconventional exploit that did not involve discovering a code vulnerability, cracking a private key, or using a flash loan. Instead, the attacker leveraged a legitimate Solana feature known as 'durable nonces' to pre-sign administrative transfers that would be executed weeks later, effectively bypassing the protocol's multisig security within minutes. This feature, designed to provide convenience, allows transactions to remain valid indefinitely until they are submitted, creating a potential security risk if not properly monitored.
The attack resulted in the theft of at least $270 million, with the stolen funds being transferred through various wallets and eventually bridged to Ethereum addresses. The primary concern is not the code itself, but rather the human layer surrounding the multisig, which failed to prevent the attacker from obtaining unauthorized transaction approvals.
The incident highlights the increasing threat of social engineering and operational security failures in DeFi protocols, emphasizing the need for enhanced scrutiny and tooling to defend against such attacks.