Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

My Amicus Brief in the Geofence Warrant Case, United States v. Chatrie

18 minutes ago

Todd Blanche, author of DOJ crypto enforcement memo, now interim AG

32 minutes ago

CFTC Sues 3 US States, Claims Sole Authority Over Prediction Markets

35 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Friday, April 3
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Drift Protocol’s $285 Million Exploit on Solana Raises Questions Over DeFi Security
Cryptocurrency & Free Speech Finance

Drift Protocol’s $285 Million Exploit on Solana Raises Questions Over DeFi Security

News RoomBy News Room2 hours agoNo Comments5 Mins Read1,631 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Drift Protocol’s 5 Million Exploit on Solana Raises Questions Over DeFi Security
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Researchers and experts are poring over Drift’s design, questioning whether certain design features or procedures could’ve thwarted its $285 million exploit.
  • The incident shows how many DeFi projects prioritize technical security over cybersecurity hygiene, according to SVRN COO David Schwed.
  • Onlookers have argued that a “time lock” would’ve given Drift the opportunity to potentially step in and prevent the attacker from siphoning the funds.

When millions of dollars in crypto are swiped from a decentralized finance protocol, tough questions often follow—and Drift Protocol’s $285 million exploit on Wednesday is no different.

The Solana-based project has been thrust into the spotlight as researchers and experts pore over its design, raising questions about whether certain design features or procedures could’ve prevented someone from pulling off one of the most lucrative DeFi attacks in the recent past.

In a post on X, Drift said a malicious actor gained unauthorized access to its platform through a “novel attack,” which granted administrative powers over Drift’s so-called security council. They added that the attack likely involved some degree of “sophisticated social engineering.”

The heist, which is among DeFi’s largest in recent history, hinged on introducing a fake digital asset on the decentralized exchange and modifying the platform’s withdrawal limits. After inflating the malicious token’s value, the attacker gained the ability to swiftly drain real liquidity from Drift by abusing borrowing mechanics.

There are indications that the exploit is linked to the Democratic People’s Republic of Korea, blockchain intelligence firm Elliptic said in a report on Thursday. They pointed to the attacker’s on-chain behavior, laundering methodologies, and network-level indicators.

With user deposits affected—and the protocol frozen as a precautionary measure—onlookers are also focusing on a core element of Drift’s design: a multisignature wallet, where signatures produced by two private keys enabled the attacker to gain sweeping powers.

Multisignature wallets represent a point of centralization for many DeFi projects, and the incident exposes the uncomfortable reality that smart contract audits can only prevent so much damage, according to SVRN COO and blockchain security expert David Schwed. 

He told Decrypt that Drift has become the latest example of how services that seek to replace financial intermediaries with code are frequently reliant on small teams and points of centralization like multisignature wallets that present cybersecurity risks.

“All of the engineers today focus on the technology side of security, they’re not focusing on the people in the process,” he said. “So yes, the protocol is decentralized, but the governance of it is centralized against five people.”

‘Yet again’

Schwed compared Drift’s lapse in security to one of the most notorious DeFi hacks, where over $625 million worth of digital assets were stolen by hackers linked to North Korea in 2022. They targeted Ronin, an Ethereum sidechain developed for the hit NFT game Axie Infinity. The attack relied on gaining access to five private keys, per blockchain security firm Chainalysis.

While blockchain analysts see the fingerprints of a nation-state, others argue the precision of the attack suggests a more intimate knowledge of the protocol. Schwed doubted that hackers linked to North Korea were involved in the hack against Drift because it feels like the attacker, possibly an insider, “knew who to target.” 

Onlookers have speculated that a “time lock” could’ve prevented the exploit from taking place so quickly. The smart contract feature restricts the execution of transactions or access to funds until a specific future time is reached, potentially providing Drift’s team with a window to step in.

“Time locks are helpful for gaining time to react to such an attack, and would have helped here—but that is not the root cause,” Stefan Byer, managing partner at Oak Security, told Decrypt. “The biggest issue was that—yet again—a privileged key was compromised.”

Still, Dan Hongfei, founder and chair of Neo Blockchain, argued that protocols like Drift that house millions of dollars in funds should not be instantly drainable.

In a post on X, he said time locks tied to critical actions like listing high-risk assets must be enforced to “prevent an attacker from completing the entire exploit chain within seconds.”

The sentiment was echoed by Or Dadosh, founder of crypto security infrastructure provider Venn Network. He also pointed to automatic circuit breakers, which enable projects to instantly pause operations if abnormal outflow velocity or volume thresholds are breached.

Several security experts wagered that Drift wouldn’t be the last DeFi project to suffer an exploit like the one that occurred on Wednesday. They noted that bad actors are increasingly turning to AI, using algorithms to gain a comprehensive understanding of their next target.

“We’ve reached a level where a bad actor can spoof your mother’s voice on a phone call,” Dadosh told Decrypt. “We live in a new age where financial attacks can surface in places and formats we couldn’t have even imagined a year ago.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

My Amicus Brief in the Geofence Warrant Case, United States v. Chatrie

18 minutes ago
Cryptocurrency & Free Speech Finance

Todd Blanche, author of DOJ crypto enforcement memo, now interim AG

32 minutes ago
Cryptocurrency & Free Speech Finance

CFTC Sues 3 US States, Claims Sole Authority Over Prediction Markets

35 minutes ago
Cryptocurrency & Free Speech Finance

Trump Admin Backs Prediction Markets With Lawsuits Against Illinois, Arizona and Connecticut

42 minutes ago
Media & Culture

Satanic Temple Wins Legal Fight Over 10 Commandments Monument in Arkansas

1 hour ago
Cryptocurrency & Free Speech Finance

Oil shock, war risk keep crypto investors on sidelines: Grayscale

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Todd Blanche, author of DOJ crypto enforcement memo, now interim AG

32 minutes ago

CFTC Sues 3 US States, Claims Sole Authority Over Prediction Markets

35 minutes ago

Trump Admin Backs Prediction Markets With Lawsuits Against Illinois, Arizona and Connecticut

42 minutes ago

Satanic Temple Wins Legal Fight Over 10 Commandments Monument in Arkansas

1 hour ago
Latest Posts

Oil shock, war risk keep crypto investors on sidelines: Grayscale

2 hours ago

Bitcoin Rally To $75K Still Possible Despite Huge Macro Challenges

2 hours ago

Drift Protocol’s $285 Million Exploit on Solana Raises Questions Over DeFi Security

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

My Amicus Brief in the Geofence Warrant Case, United States v. Chatrie

18 minutes ago

Todd Blanche, author of DOJ crypto enforcement memo, now interim AG

32 minutes ago

CFTC Sues 3 US States, Claims Sole Authority Over Prediction Markets

35 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.