Drift Protocol suffered a $280M exploit via sophisticated admin takeover using durable nonce vulnerabilities; ZachXBT raises concerns about Circle's USDC response.
Security & Exploits ·
Drift Protocol disclosed a $280 million exploit occurring on Wednesday, attributed to unauthorized transaction approvals enabled through durable nonce mechanisms. The protocol characterized the attack as "sophisticated" and involving an admin takeover. The incident has drawn scrutiny beyond Drift itself, with crypto investigator ZachXBT publicly criticizing Circle's handling of the USDC stablecoin response to the exploit.
Durable nonce vulnerabilities allowed attackers to execute transactions without the standard single-use authorization safeguards typical in blockchain systems. By compromising admin privileges, the attacker gained the ability to approve transactions that would normally require additional verification steps, effectively bypassing core security layers designed to protect user assets on the protocol.
The full extent of Circle's involvement in the exploit's aftermath and the specific nature of ZachXBT's criticism remain unclear from available accounts. Similarly, details on whether Drift has recovered any funds or implemented immediate remediation measures have not yet been disclosed.