DeFi platform Drift suspends deposits and withdrawals after crypto hack

The firm posted on X that it was investigating ‘unusual activity’ on the protocol, telling users that it was not an April Fool’s joke.

Security researchers estimate losses at up to $240 million, blaming governance security as the chief vulnerability after the attcker infiltrated a multisig upgrade a week ago.

One independent researcher observed: “This isn’t a technical vulnerability, It’s a governance catastrophe. Drift’s smart contracts themselves were fine. The problem was:
• Multisig handoff process failure
• Handing the hacker a “master key”
• All subsequent operations were “legitimate” calls”

In summary: “The essence of the Drift hack = Unified Liquidity Pool (risk concentration) × Multisig Vulnerability (privilege loss) × Excessive Admin Privileges (no checks)”

“At the cost of $240 million, it sounds the alarm for the entire DeFi industry.”

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin