A recent attack on Drift Protocol resulted in the theft of at least $270 million, achieved not through a traditional hack or code exploit, but by leveraging a legitimate Solana feature known as 'durable nonces.' This feature, designed for convenience and security, allows transactions to remain valid indefinitely, bypassing the usual time constraints of Solana's transaction system. The attacker exploited this by pre-signing administrative transfers weeks in advance, which were then executed in a matter of minutes, circumventing the protocol's multisig security measures. The exploit highlights the vulnerability of human oversight in multisig setups and the potential for social engineering attacks in DeFi protocols.
The stolen funds, totaling over $270 million across various tokens, were transferred through intermediary wallets and eventually bridged to Ethereum addresses, with some critics pointing out the failure of certain platforms to freeze the stolen assets in a timely manner. The incident underscores the growing concern of operational security failures and social engineering attacks in the DeFi space, where the line between legitimate features and exploitable vulnerabilities can be thin.