The Drift Protocol attack was not a traditional hack, as it did not involve exploiting a bug in the code or cracking a private key. Instead, the attacker leveraged a legitimate Solana feature called 'durable nonces' to trick Drift's security council into pre-approving transactions that would be executed at a later time. This feature allows transactions to remain valid indefinitely, creating a security risk if not properly monitored. The attacker obtained the required signatures from two council members, then executed the transactions, gaining control of Drift's protocol-level permissions and introducing a fraudulent withdrawal mechanism.
The stolen funds, totaling over $270 million, were transferred to various wallets and eventually bridged to Ethereum addresses. The attack highlights the importance of addressing social engineering and operational security failures in DeFi protocols, as well as the need for improved tooling and interface changes to defend against durable nonce exploits.