Résumé
On 1 April 2026, attackers drained about $285 million from Drift, the largest perpetual-futures exchange on Solana, in roughly twelve minutes, more than half of everything the protocol held. There was no smart-contract bug. The contracts worked exactly as written. The attackers, later tied to North Korea's Lazarus operations, spent months socially engineering the people with privileged access, then abused a Solana feature called durable nonces to get the protocol's multisig signers to approve, in advance and without realising it, the transactions that handed over control. Once they had admin rights they whitelisted a worthless token as collateral, deposited a pile of it, and borrowed out the real money. It is the case that proves the modern crypto heist is an operations and social-engineering problem, not a Solidity one.
How it happened
From the autumn of 2025, the attackers ran a long con. Posing as a quantitative trading firm courting the project, they built trust with Drift contributors and worked their way into cloud infrastructure and, critically, into the trust of the people who controlled the protocol's privileged multisig. The technical key was Solana's durable nonces, a legitimate feature that lets a transaction be signed now and submitted validly much later, instead of expiring within seconds like a normal Solana transaction. Using that, the attackers got the Security Council multisig members to sign transactions that looked routine but were actually pre-authorising an administrative takeover, to be executed at the attackers' chosen moment. A migration with no timelock then stripped the remaining safeguards instantly. With admin control, they whitelisted a worthless token of their own as acceptable collateral, deposited a large amount of it, and withdrew roughly $285 million in real assets, USDC, SOL, and ether, bridging it to Ethereum within hours.
Who was behind it
Blockchain-intelligence firms attributed the theft to North Korea with medium-to-high confidence, and Drift's own post-mortem tied it to the actors behind the October 2024 Radiant Capital hack, a Lazarus-adjacent cluster tracked as UNC4736 (also called AppleJeus or Citrine Sleet). It is the same national operation, and often the same playbook of patient social engineering, behind Bybit, the Ronin bridge, and, going back further, Sony Pictures and WannaCry. The trend it confirms is stark: by 2026 the most expensive crypto attacks are no longer clever contract exploits but social engineering against the humans and processes that hold privileged access.
The aftermath
The funds were bridged out and converted quickly, and no recovery was confirmed; most of the $285 million was gone. Drift's total value locked fell from around $550 million to under $300 million almost immediately, making it the largest DeFi theft of 2026 at the time and the second largest in Solana's history after the $326 million Wormhole bridge hack. The deeper damage was to a comfortable assumption: that a multisig with several independent human signers is a strong control. Here it was the control that got captured, because the signers were manipulated into approving the takeover themselves.
Why Drift still matters
Drift shows that privileged access is the prize, and people and process are the weak points. The contracts were fine; the governance and signing process around them was not. The defences are operational, not cryptographic: treat every signer's workstation and the whole signing workflow as a high-value target; never blind-sign, and have signers independently decode and simulate exactly what each transaction does before approving; be deeply suspicious of any mechanism, like durable nonces, that lets a signature be executed later than expected, and constrain or monitor it; require timelocks on administrative and migration actions so a takeover cannot complete instantly and can be caught and cancelled; and train contributors against the long, patient social-engineering campaigns Lazarus specialises in. The lesson rhymes with Bybit: the keys were never the weak link, the humans approving with them were.
Comment le corriger
- Treat the signing and governance infrastructure as fully compromised: revoke and rotate all privileged keys and rebuild the multisig with signers verified on clean systems.
- Trace and publicly flag the stolen funds immediately, and coordinate with exchanges and bridges to freeze what is still reachable.
- Remove any standing administrative path that lacks a timelock, so no single approval can hand over control instantly.
Comment l’éviter
- Put timelocks on all administrative, migration, and collateral-whitelisting actions, so a malicious change is delayed long enough to be detected and cancelled.
- Mandate clear-signing: signers must independently decode and simulate each transaction on isolated devices, and never blind-sign a pre-built payload.
- Constrain and monitor durable nonces and any feature that lets a signed transaction execute later than expected.
- Harden signer endpoints and contributor accounts against long-running social engineering, and verify out-of-band any party requesting privileged interaction.
- Require multiple independent reviews of decoded calldata before any privileged transaction is approved.
Références
Vulnérabilités liées
Tout Web3 →- CRITICALWEB3-WAZIRX-2024
On July 18, 2024 Indian exchange WazirX lost approximately $230M (about $234.9M) from a Safe (Gnosis) 4-of-6 multisig wallet held under a custody arrangement with Liminal (five WazirX keys plus one Liminal key). The attack was a blind-signing exploit: signers reviewed benign transaction details in the manipulated Liminal interface while the payload actually signed differed, authorizing a delegatecall (function selector 0x804e1f0a) that overwrote slot0 of the Safe proxy and repointed its implementation to an attacker-controlled contract (0xef279c2ab14960aa319008cbea384b9f8ac35fc6). Once the proxy pointed to attacker logic the wallet was fully controlled without further keys, and it was drained. The theft was attributed to North Korea's Lazarus Group, later confirmed in a joint statement by the US, South Korea and Japan in January 2025. Funds were laundered via Tornado Cash; victims are being repaid through a court-approved restructuring (resumed October 2025, BitGo custody) rather than direct recovery.
- CRITICALWEB3-DMM-BITCOIN-2024
On May 31, 2024 Japanese exchange DMM Bitcoin lost 4,502.9 BTC, worth approximately $305M-$308M at the time. The compromise was a supply-chain social-engineering chain that did not breach DMM directly: a TraderTraitor operator posing as a recruiter on LinkedIn sent an employee of wallet-software vendor Ginco a malicious Python script disguised as a GitHub pre-employment coding test. The malware (RN Loader / RN Stealer) harvested SSH keys, credentials and cloud configurations; weeks later attackers used stolen session cookies to impersonate the Ginco employee, access the unencrypted communications system linked to DMM, and tamper with a legitimate withdrawal request submitted by a DMM employee, redirecting 4,502.9 BTC to attacker addresses. US and Japanese authorities (FBI, DC3, Japan's NPA) attributed the theft to North Korean actors tracked as TraderTraitor (Jade Sleet / UNC4899), associated with the Lazarus Group. Funds were not recovered; DMM Bitcoin shut down and transferred accounts to SBI VC Trade.
- CRITICALWEB3-MULTICHAIN-2023
On July 6, 2023, the cross-chain bridge Multichain saw unusually large unauthorized withdrawals totaling about $126 million (roughly $120 million from the Fantom bridge plus smaller amounts on Moonriver and Dogechain), with broader figures up to ~$210 million once a separate tranche moved on July 10. The root cause was an admin/MPC private-key compromise driven by centralization rather than a contract bug. Multichain's withdrawals were nominally signed by MPC nodes each holding a key share, but in practice the MPC servers all ran under CEO Zhaojun's personal cloud account and the key material (hardware wallets, mnemonic phrases) sat on devices he personally controlled, so the multi-party threshold collapsed to a single point of control; a Singapore court later found he held ultimate privileges over the assets. After Zhaojun was detained by Chinese police in May 2023 and his devices, hardware wallets, mnemonic phrases and the MPC wallet were confiscated, control passed to whoever physically held the keys, and funds were moved from MPC-controlled pool addresses to unknown wallets. The event is widely treated as a possible insider job or rug pull, though that intent was never proven; Multichain ceased operations indefinitely and funds were not recovered.
- CRITICALWEB3-HARMONY-HORIZON-2022
On June 24, 2022, Harmony's Horizon bridge was exploited for approximately $99.7 million. The Ethereum-side bridge was secured by a 5-validator multisig configured at a low 2-of-5 threshold, so compromising just two keys gave full control of the funds. Per Harmony's post-mortem the private keys were not stored in plaintext but were doubly encrypted via a passphrase and a key management service, with no single machine holding multiple plaintext keys; the attacker nonetheless breached Harmony's hot signing infrastructure and was able to access and decrypt several keys, including those used to sign the unauthorized transfers, because the decryption capability lived within reach of the compromised environment. With two decrypted keys meeting the threshold, the attacker signed and confirmed the drain across 11 transactions (the 2 refers to the signature threshold, not the transaction count). The FBI and Elliptic attributed the theft to North Korea's Lazarus Group (APT38); the stolen assets were swapped to Ether and laundered through Tornado Cash and later RAILGUN.
- CRITICALWEB3-SIG-REPLAY-2022
Signature replay occurs when a signed message lacks binding context (nonce, chainId, or an EIP-712 domain separator), so a signature valid for one execution can be re-submitted on another call or another EVM chain. The canonical 2022 case is the Optimism/Wintermute loss of 20,000,000 OP tokens disclosed June 9, 2022: Wintermute provided a Gnosis Safe address deployed on Ethereum mainnet but not on Optimism. Because the Gnosis Safe factory's original deployment transaction used a pre-EIP-155 signature, its hash covered only six RLP fields (nonce, gasPrice, gas, to, value, data) and omitted chainId, so anyone could rebroadcast the identical signed transaction on Optimism. An attacker replayed that deployment to recreate the factory and Safe at the same counterfactual address on L2, gained control of the contract account before the rightful owners, and swept the 20M OP. The same low-level flaw appears in application contracts that ecrecover a digest missing nonce/chainId, letting one signed approval be replayed repeatedly.
- CRITICALWEB3-KELPDAO-LAYERZERO-2026
On April 18, 2026, North Korea's Lazarus Group drained about 116,500 rsETH (roughly $292 million) from KelpDAO's LayerZero-based bridge, the largest DeFi exploit of the year. No smart contract was broken; the contracts did exactly what they were written to do. The attack was against the bridge's off-chain verification. rsETH's LayerZero channel was configured to trust a single verifier (a 1-of-1 DVN), so the attackers compromised LayerZero's internal RPC nodes, knocked out the honest external node with a denial-of-service flood, and forced that single verifier to attest to a cross-chain message that never really happened. The Ethereum side then released unbacked rsETH from escrow, leaving wrapped rsETH stranded across more than twenty chains and triggering a bank-run across DeFi.