Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Crypto Security, From Defense to Incident Response
safu-bible.com
LATEST
One Fingerprint Tap Unlocks Your Wallet — Does That Mean You're Safer? What Passkeys Don't Tell You: They're One Factor, Not Your Only Line of Defense  ·  Even Microsoft's Own Account Got Hijacked: Hackers Used 13 Million Followers to Push a Fake "$Clippy" Token in 30 Minutes  ·  $285 Million Drained in 12 Minutes: How Attackers Turned Pre-Signed Transactions Against Multisig Itself  ·  Two Test Transfers Slipped Past Risk Controls, Then $388 Million Vanished in 30 Minutes: Bitget Hit by a Third-Party Security Zero-Day  ·  $1.3 Billion Lost to Hacks in H1 2026, Code Bugs Only 11%: Crypto Security's Battlefield Has Moved  ·  Not a Single Line of Code Was Changed, Yet $8.7 Million Vanished: How Moonwell's Price Oracle Got Exploited
incident-analysis

$285 Million Drained in 12 Minutes: How Attackers Turned Pre-Signed Transactions Against Multisig Itself

30-Second Version · For the impatient
Six months building trust, then a transaction pre-signed now and executed later — multisig signers approved their own losses without ever knowing it.

Full Explanation +
01 · Why did this happen?

Durable nonces are a normal Solana feature — why did they become an attack tool?

Durable nonces were designed to solve a real problem: ordinary Solana transactions expire if not submitted shortly after signing, which is inconvenient for legitimate use cases that need signing coordinated across devices or execution delayed for a review process. Durable nonces let a transaction be signed once and held for submission at any future point without expiring.

The feature itself isn't the problem. The problem is the time gap it creates between "review at the moment of signing" and "what actually executes later." The attackers exploited exactly that gap — getting signers to approve at a moment when nothing looked suspicious, while the actual malicious effect only triggered weeks later.

02 · What is the mechanism?

Why did Drift remove its timelock just four days before the attack? Was this attacker manipulation?

Public reporting doesn't clearly establish whether the decision to remove the timelock was directly influenced by the attackers, but the timing coincidence itself is worth flagging. Whether the removal was an autonomous operational decision by the team, or indirectly shaped by the trust relationship the attackers had spent months building, the outcome is the same: the mechanism that should have provided a buffer window for other members to catch an anomalous transaction simply wasn't there during the critical attack window.

This points to a broader principle: any change to governance security settings — especially lowering thresholds or removing safeguards — should be treated as a high-risk action requiring independent review, not just routine internal sign-off.

03 · How does it affect me?

What role did the fake CVT Token play in the overall attack?

CVT (CarbonVote Token) was a prop the attackers manufactured to make the final withdrawal look legitimate on-chain. Through Wash Trading (buying and selling from themselves to fabricate trading volume) and seeding a small amount of real liquidity, the attackers tricked Drift's oracle system into treating CVT as having genuine market value, allowing it to be recorded as legitimate collateral within the system. This step made the massive withdrawal executed later via pre-signed transactions appear, from the system's logical standpoint, to be backed by a corresponding asset — rather than funds vanishing out of nowhere. This also illustrates how sophisticated the attack was: the attackers didn't just infiltrate people and governance processes — they simultaneously manipulated on-chain price discovery, timing both attack tracks to converge on the same day.

04 · What should I do?

What concrete lessons can other protocols or DAOs take from this?

A few actionable takeaways: First, governance timelocks shouldn't be treated as a parameter that can be casually adjusted — any proposal to remove or shorten a timelock should itself trigger additional multi-party scrutiny. Second, for chains supporting durable nonces or similar delayed-execution mechanisms, teams should regularly audit for unexecuted pre-signed transactions rather than assuming "nothing bad has happened yet" means safety. Third, maintain ongoing identity verification and separation of duties toward external partners — even ones with a long-established relationship who have put in real money — and never let a single external contact hold both code access and governance-level influence.

The most fundamental point: multisig protects the moment of decision, not the long-term validity of that decision. Teams need additional mechanisms to ensure what a signer sees at signing time matches what actually executes later.

Full Content +

On April 1, 2026, decentralized derivatives protocol Drift Protocol lost $285 million across 31 withdrawals in roughly 12 minutes. What shocked the security community most wasn't the dollar amount — it was that the attack never touched a single line of vulnerable code. Drift's smart contracts had no logic errors to point to. What actually broke was the trust mechanism that multi-signature wallets depend on to function at all.

Six Months of Groundwork: Build Trust First, Attack Later

The operation traces back to fall 2025. A group posing as a quantitative trading firm — technically fluent and seemingly credible — began approaching Drift contributors at crypto conferences. They understood how Drift operated well enough to hold substantive discussions about trading strategies and vault integrations, and maintained contact over time through a Telegram group. Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift and deposited over $1 million — real capital that further reinforced the team's trust. Through February and March, both sides continued what looked like ordinary technical integration discussions. Drift later attributed the attack, with medium confidence, to UNC4736, a North Korean state-sponsored group also tracked as AppleJeus, Citrine Sleet, and Golden Chollima, based partly on overlapping fund flows and operational personas, with links traced back to the October 2024 Radiant Capital hack.

Two Entry Points: A Code Repository and a Beta-Test App

Once trust was established, the attackers moved into actual technical infiltration — using two entirely separate methods to reduce the odds that any single contributor would catch on. The first: convincing one contributor to clone a malicious code repository containing a weaponized Visual Studio Code project file (tasks.json) that automatically executed malicious code the moment the project was opened — no additional click required. The second: persuading a different contributor to beta-test a disguised wallet product through Apple's official TestFlight platform. Running both paths in parallel meant that even if one contributor grew suspicious, the other path could still proceed.

The Actual Mechanism: Pre-Signed Transactions and Durable Nonces

Having gained initial access, the attackers didn't strike immediately — they spent nearly three weeks carefully staging the final blow. On March 11, 2026, they withdrew 10 ETH from Tornado Cash as seed funding. On March 12, they deployed a fabricated Token called CVT (CarbonVote Token). Between March 23 and 30, the attackers exploited Solana's durable nonce feature — a legitimate, officially supported mechanism designed to let a transaction be signed once and executed later without expiring — to create a series of accounts holding transactions that could be "pre-signed now, executed later." They used this to get Drift's Security Council multisig signers to unknowingly sign transactions that appeared routine, but which actually carried hidden authorizations for critical administrative actions. The more critical move came on March 27: Drift migrated its Security Council to a "2-of-5 threshold with zero timelock" configuration — removing the buffer period that would normally give the team a window to detect anomalies and intervene, just four days before the attack. Simultaneously, the attackers used Wash Trading and minimal liquidity seeding to manufacture an artificial "market value" for the CVT token, tricking Drift's oracles into treating this entirely fictitious asset as legitimate collateral worth hundreds of millions of dollars. By March 30, everything was in place. On April 1, the harmless-looking durable-nonce transactions signed weeks earlier were submitted and executed all at once — 31 withdrawals, completed in 12 minutes, draining $285 million instantly.

Why Multisig Didn't Stop This

Multisig's core assumption is that multiple independent signers won't make the same bad call at the same time. This incident shows that if attackers can get a signer to approve a transaction under seemingly harmless conditions — while the transaction's real effect only activates at some future point — the traditional "review at signing time" defense fails completely. At the moment of approval, the signer is reviewing what looks normal right now, not the hidden authority the transaction may be given in the future. Removing the timelock made things worse still: even if a contributor later noticed something was off, there was no buffer window left to freeze or revoke the already pre-signed transactions.

What This Means for Your Money

If you're evaluating whether a DeFi protocol is safe, "does it have multisig" is no longer enough of a question. You need to dig further: does governance enforce a mandatory timelock, has the signing threshold been recently lowered, and does the team use pre-signing mechanisms that could be abused this way. A protocol that advertises multisig protection but removes its timelock at a critical moment may offer far less protection than it appears to on paper.

Sources: $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation - The Hacker News, North Korean Hackers Attack Drift Protocol In $285 Million Heist - TRM Labs, Drift Protocol Hack: How Privileged Access Led to a $285M Loss - Chainalysis
Diagram
Drift Protocol Attack Timeline從六個月社交工程鋪陳,到撤除時間鎖與偽造抵押品,最終12分鐘完成2.85億美元提款Drift Protocol: Timeline of a $285M AttackFall 2025Trust-buildingbegins atconferencesDec 2025-Mar 2026Vault deposit,repo clone +TestFlight appMar 23-30Durable-noncepre-signed txns +timelock removed(27)Mar 12-30CVT tokenwash-traded asfake collateralApr 131 withdrawals$285M in 12 minTrust-building (blue) set up the access; timelock removal + fake collateral (red) made the 12-minute drain possibleSAFU Bible · safu-bible.com
Feel free to share. Please credit the source.
Ask a Question
Please enter at least 10 characters
Related Articles
$1.5 Billion, One Tampered Signing Interface: Why Multisig Couldn't Stop Crypto's Biggest Heist
incident-analysis · Aug 26
One Fingerprint Tap Unlocks Your Wallet — Does That Mean You're Safer? What Passkeys Don't Tell You: They're One Factor, Not Your Only Line of Defense
beginners · Oct 05
$1.3 Billion Lost to Hacks in H1 2026, Code Bugs Only 11%: Crypto Security's Battlefield Has Moved
fundamentals · Oct 05
Splitting Your Seed Phrase Into Five Pieces — Does It Actually Make You Safer? The Real Tradeoffs of Shamir Backup
wallet-security · Sep 03
Related News
More Related Topics