Social Engineering and Governance Game – Drift Protocol $285 Million Attack Analysis

Drift Protocol is a leading decentralized exchange (DEX) for perpetual contracts within the Solana ecosystem. Its core advantage lies in supporting high leverage (up to 20x) for perpetual contract trading, making it one of the most popular DeFi protocols within the Solana ecosystem. By March 2026, its total value lo…

Drift Protocol is a leading decentralized exchange (DEX) for perpetual contracts within the Solana ecosystem. Its core advantage lies in supporting high leverage (up to 20x) for perpetual contract trading, making it one of the most popular DeFi protocols within the Solana ecosystem. By March 2026, its total value locked (TVL) had exceeded $1.2 billion, ranking third among Solana DEXs, surpassing even older protocols like Serum.

To secure the platform's funds, Drift Protocol implemented a seemingly robust multi-signature governance mechanism. Its security committee uses a 5/5 multi-signature structure, meaning any operation involving core permission changes or fund transfers must be signed by all five security committee members before execution. Additionally, the platform incorporated Solana’s unique "Durable Nonces" mechanism, providing timestamp validation for multi-signature transactions to prevent transaction replay or tampering. In theory, this structure provides a high level of security, ensuring that even if one or two multi-signature members' private keys are compromised, attackers cannot complete core operations. However, the subsequent attack proved that no matter how advanced the technical architecture, it cannot withstand human-layer breaches.

Complete Attack Reconstruction

This attack was not a sudden "flash attack," but rather a well-planned "trust hunting" operation that spanned six months. According to tracing by security organizations, the attackers belonged to a sub-branch of the North Korean state-sponsored hacker group Lazarus Group, specifically UNC4736. This group had previously conducted high-value attacks on the Web3 ecosystem, with total losses exceeding $2 billion. The full attack timeline clearly demonstrates the core logic of "trust infiltration":

  • Infiltration and Trust-Building Phase (October 2025 - February 2026):The attackers initially forged the identity of a Singapore-based quantitative trading firm. They registered the company, created a professional website, and even generated LinkedIn and Twitter profiles for core team members with real trading records. The attackers then attended Solana ecosystem offline summits and online technical forums, proactively reaching out to core team members of Drift Protocol. They offered optimization suggestions for the platform's perpetual contract mechanisms, including fixing a potential fee calculation bug. These contributions earned the attackers the trust of Drift's core contributors and even granted them direct communication privileges with the security committee members.
  • Pre-signed Transaction Inducement Phase (March 23 - March 30, 2026):After gaining trust, the attackers began implementing the core inducement step. They exploited the Solana ecosystem developers' trust in the "Durable Nonces" mechanism by designing a seemingly reasonable test scenario: claiming they needed to test the compatibility of Drift’s "multi-signature offline signing" and asking security committee members to pre-sign a few "test transactions for cross-chain asset deposits." Due to the attackers' prior technical contributions, they gained enough trust from the team, leading two of the five security committee members to blindly sign the transactions without verifying their content on-chain. These pre-signed transactions were, in fact, malicious transactions intended to transfer administrative permissions of the Drift protocol to the attackers.
  • Attack Execution Phase (April 1, 2026):On April 1, around 12:00 UTC, the attackers first executed a small test withdrawal transaction from the Drift insurance fund. This operation served to confirm the platform’s monitoring system was functioning properly and to lull the team into a false sense of security. About one minute later, the attackers quickly executed two pre-signed Durable Nonce transactions, with just a 4-Solana slot (approximately 8 seconds) gap between them. The first transaction created and approved a proposal to transfer Drift's administrative permissions to the attackers’ control address; the second transaction executed that proposal. Since Drift's multi-signature mechanism lacked a time lock (meaning once a proposal was approved, it could be immediately executed), the attackers were able to complete the entire permission transfer process in just 10 seconds and effectively took control of the Drift protocol.
  • Asset Transfer and Escape Phase:After obtaining administrative permissions, the attackers immediately began converting assets. They created a false CVT token market on Drift and manipulated the price oracle to inflate the token price to $1. Then, they disabled the platform’s withdrawal protection mechanism, allowing large assets to be withdrawn without limits. Finally, they transferred assets from the insurance fund and user margin accounts to addresses controlled by the attackers. The entire asset transfer process took about 12 minutes, with all transactions executed under the attackers' control, without triggering any security alerts.

Drift’s security team only detected anomalies through on-chain monitoring tools after the attackers had transferred most of the assets to cross-chain bridge addresses. By this time, the attackers had spread the assets across Solana, Ethereum, Tron, and other blockchains. The team could only suspend all platform transactions at 12:12 UTC. Ultimately, the total loss from this attack was estimated by blockchain security company CertiK to be around $285 million.

Technical Analysis

The core breach in this attack was not a vulnerability in Drift Protocol’s smart contract code but the human layer of its multi-signature governance mechanism. The attackers exploited the "Durable Nonces" feature and combined it with social engineering tactics to bypass what appeared to be a robust technical defense. The core logic of the technical implementation can be broken down into two key parts:

  • Weaponization of the Durable Nonces Mechanism:Solana’s "Durable Nonces" feature was originally designed to solve the issue of offline signing for hardware wallets. It allows users to pre-sign transactions offline, and the signed transactions remain valid until the nonce is consumed. The attackers, however, turned this feature into a "time bomb": they created four Durable Nonce accounts, two linked to Drift security committee members' legitimate addresses and two controlled by the attackers. By inducing the committee members to pre-sign transactions for these linked accounts, the attackers effectively obtained the permission to execute malicious transactions at any future time, without ever needing to access the members' private keys.
  • Loss of Control Over the Multi-Signature Permissions:Drift Protocol uses a 2/5 multi-signature threshold, meaning only two out of the five security committee members need to sign off for core operations to execute. However, more critically, the multi-signature mechanism lacked any time lock. This meant that once the attackers obtained enough signatures, they could execute the permission transfer immediately, without any response time for the team. Additionally, Drift's multi-signature validation only verified if the signatures came from legitimate members, but it did not check the specific content of the transactions, which allowed the attackers' malicious pre-signed transactions to pass through undetected.

Impact and Aftermath

This attack not only dealt a devastating blow to Drift Protocol but also exposed systemic flaws in the entire DeFi governance mechanism:

  • Platform Reputation and User Attrition:After the attack, Drift Protocol’s TVL dropped by over 80% within 48 hours, from $1.2 billion to under $200 million. A large number of users withdrew their deposits due to a lack of trust in the platform’s security mechanisms. As of April 21, 2026, the TVL had only recovered to around $300 million, with user numbers down by 60% compared to before the attack. This was nearly a fatal blow for a perpetual contract DEX that relies on user liquidity.
  • Industry Trust Crisis:The attack directly exposed a core vulnerability in DeFi governance mechanisms: even the most robust technical structures cannot resist social engineering attacks. Previously, DeFi ecosystems believed that multi-signature mechanisms were the "last line of defense" for protocol security. However, Drift's case proved that if multi-signature members lack sufficient security awareness, this defense line can quickly collapse. This has sparked a reevaluation of "human factors" in governance mechanisms across the industry: how to ensure governance efficiency while minimizing risks from human error.
  • Asset Flow and Difficulty in Recovery:On-chain tracking data showed that the attackers transferred about 40% of the stolen assets to the Ethereum network, converting them into WETH; 30% to the Tron network, converting to USDT; and the remaining 30% stayed within Solana, being swapped for SOL on DEXs like Serum and Raydium. The attackers then split the assets into over 500 newly created addresses, with each transfer not exceeding $100,000, aiming to evade large transaction alerts from monitoring platforms like Chainalysis and Elliptic. As of April 21, 2026, less than 0.05% of the stolen assets had been recovered, and asset recovery efforts have effectively stalled.

References

  • "Two Transactions, $285 Million Vanished: Full Analysis of the Drift Protocol Attack":Foresight News
  • "47 Encryption Incidents Retrospective: All Fell Victim to the Same Human Vulnerability":Cointeeth
  • "Drift Protocol’s $285 Million Theft: Did Hackers Deliver the Fatal Blow to DeFi in the Bear Market?":AiCoin
  • "Two Transactions, $285 Million Vanished: Full Analysis of the Drift Protocol Attack":Foresight News

Insight Report Source: Global Cybersecurity Alliancehttps://www.gcsa.org