Drift Protocol exploited via durable nonce attack; malicious actor seized Security Council administrative powers.
Security & Exploits ·
A malicious actor executed a novel attack involving durable nonces against Drift Protocol, gaining unauthorized access and seizing control of the protocol's Security Council administrative powers. The breach unfolded earlier today without prior warning to users or the public.
The operation was highly sophisticated, involving multi-week preparation and staged execution. The attacker leveraged durable nonce accounts to pre-sign transactions that delayed their execution, enabling a rapid takeover once the administrative access was secured. This layered approach suggests careful planning to evade detection or intervention.
The full scope of the attack—including how many transactions were affected, what actions the attacker took with the seized powers, or whether funds were moved—remains unclear from available statements. Recovery measures and a detailed technical postmortem have not yet been announced.