DPRK Link: Elliptic says the Drift Protocol exploit shows behavioral and laundering patterns consistent with DPRK operations, marking what could be the eighteenth such incident this year.
Circle's inaction during the Drift Protocol attack raises concerns about centralized stablecoin reliability and regulatory oversight effectiveness. Circle took no action during Drift Protocol attack, says investigator.
The blockchain analytics firm pointed to cross-chain laundering patterns and Solana-specific tracing challenges that mirror prior North Korean state-linked operations
Drift Protocol's reported $285M hack highlights Solana DeFi's human weak point, with social engineering, not core code flaws, behind the breach.
Drift Protocol, a major Solana-based DeFi exchange, has suffered a $285 million social engineering-driven exploit that weaponized a compromised administrator key rather than any code flaw.
Drift Protocol, a Solana-based derivatives decentralized exchange (DEX), has suffered a major exploit that drained an estimated $200 million to $285 million in user assets, intensifying security concerns across the Solana DeFi ecosystem and reviving questions about oracle design and admin-key risk. The attack occurred on Wednesday UTC (early Thursday in South Korea), according to on-chain tracing and statements from the project.
The exploit highlights vulnerabilities in DeFi protocols, potentially undermining trust and prompting stricter security measures industry-wide. Drift Protocol exploiter doubles down on Ethereum after siphoning $285 million in assets.
Drift Protocol Vault Loses $270M in Potential Exploit
ZachXBT accused Circle of inaction while stolen USDC moved through its own bridge during the Drift hack, weeks after it froze 16 legitimate business wallets.
An attacker drained $285 million from Solana's largest perpetual futures exchange using a fabricated token, manipulated oracles, and a compromised admin key.
Drift said a durable nonce attack helped drive its Solana exploit, as critics questioned why stolen USDC moved for hours without a freeze.
Drift said Wednesday's $280 million exploit was a result of unauthorized transaction approvals, facilitated through durable nonce mechanisms.