Connect with us
DAPA Banner

Crypto World

Here is how Drift attackers drained more than $270 million using a Solana feature designed for convenience

Published

on

(Drift/CoinDesk)

The attack on Drift Protocol was not a hack in the traditional sense.

Nobody found a bug or cracked a private key. There wasn’t a flash loan exploit or manipulated oracle either.

Instead, an attacker used a legitimate Solana feature, ‘durable nonces,’ to trick Drift’s security council into pre-approving transactions that would be executed weeks later, at a time and in a context the signers never intended.

The result was a drain of at least $270 million that took less than a minute to execute but more than a week to set up.

Advertisement

What durable nonces are and why they exist

On Solana, every transaction includes a ‘recent blockhash,’ essentially a timestamp that proves the transaction was created recently. That blockhash expires after about 60 to 90 seconds. If the transaction is not submitted to the network within that window, it becomes invalid. This is a safety feature and helps prevent old, stale transactions from being replayed later.

Durable nonces override that safety feature. They replace the expiring blockhash with a fixed ‘nonce,’ a one-time code stored in a special onchain account, that keeps the transaction valid indefinitely until someone chooses to submit it.

The feature exists for legitimate reasons. Hardware wallets, offline signing setups, and institutional custody solutions all need the ability to prepare and approve transactions without being forced to submit them within 90 seconds.

But indefinitely valid transactions create a problem. If one can get someone to sign a transaction today, it can be executed next week or next month, per the system’s hardcoded rules. The signer has no way to revoke their approval once it is given, unless the nonce account is manually advanced, which most users do not monitor.

Advertisement

How the attacker used them

Drift’s protocol was governed by a ‘Security Council multisig,’ a system in which multiple people (in this case, five) share control, and any action requires at least two of them to approve. Multisigs are a standard security practice in DeFi, where the idea is that compromising a single person is not enough to steal funds.

But the attacker did not need to compromise anyone’s keys. All they needed were two signatures, and they appear to have obtained them through what Drift describes as “unauthorized or misrepresented transaction approvals,” meaning the signers likely thought they were approving a routine transaction.

Here is the timeline Drift published in a Thursday X post.

On March 23, four durable nonce accounts were created. Two were associated with legitimate Drift Security Council members. Two were controlled by the attacker. This means the attacker had already obtained valid signatures from two of the five council members, locked into durable nonce transactions that would not expire.

Advertisement

On March 27, Drift executed a planned Security Council migration to swap out a council member. The attacker adapted. By March 30, a new durable nonce account appeared, tied to a member of the updated multisig, indicating the attacker had re-obtained the required two-of-five approval threshold under the new configuration.

On April 1, the attacker executed.

First, Drift ran a legitimate test withdrawal from its insurance fund. Approximately one minute later, the attacker submitted the pre-signed durable nonce transactions. Two transactions, four slots apart on the Solana blockchain, were enough to create and approve a malicious admin transfer, then approve and execute it.

Within minutes, the attacker had full control of Drift’s protocol-level permissions. They used that control to introduce a fraudulent withdrawal mechanism and drain the vaults.

Advertisement
(Drift/CoinDesk)

What was taken and where it went

Onchain researchers tracked the fund flows in real time. The breakdown of stolen assets, compiled by security researcher Vladimir S., totaled roughly $270 million across dozens of tokens.

The largest single category was $155.6 million in JPL tokens, followed by $60.4 million in USDC, $11.3 million in CBBTC (Coinbase wrapped bitcoin), $5.65 million in USDT, $4.7 million in wrapped ether, $4.5 million in DSOL, $4.4 million in WBTC, $4.1 million in FARTCOIN, and smaller amounts across JUP, JITOSOL, MSOL, BSOL, EURC, and others.

(Vladimir S./ZachXBT/Arkham Intelligence/CoinDesk)

The primary drainer wallet was funded eight days before the attack via NEAR Protocol intents but remained inactive until execution day. Stolen funds were transferred to intermediary wallets that were funded just the day before via Backpack, a decentralized crypto exchange that requires identity verification, potentially giving investigators a lead.

From there, funds moved to Ethereum addresses via Wormhole, a cross-chain bridge. Those Ethereum addresses had been pre-funded using Tornado Cash, the sanctioned privacy mixer.

ZachXBT, a prominent onchain investigator, noted that over $230 million in USDC was bridged from Solana to Ethereum via Circle’s CCTP (Cross-Chain Transfer Protocol) across more than 100 transactions.

He criticized Circle, the centralized issuer of USDC, for not freezing the stolen funds during a six-hour window after the attack began around noon Eastern time.

Advertisement

The attack was also reminiscent of recent social engineering attempts, using tactics similar to those seen before, according to a social media post by a user who goes by ‘Temmy.’ “we’ve seen this before. we’ve seen this so many times,” the user said.

“bybit. $1.4 billion. the attacker compromised the signing infrastructure and tricked signers into authorizing malicious transactions. same concept. social engineering. not code. ronin bridge. $625 million. compromised validator keys. same story. cetus protocol. $223 million. different method but same result. hundreds of millions gone.” the post said.

What was not compromised

What failed was the human layer around the multisig. Durable nonces allowed the attacker to separate the moment of approval from the moment of execution by more than a week, creating a gap in which the context of the signed document no longer matched the context in which it was used.

All deposits into Drift’s borrow-and-lend products, vault deposits, and trading funds are affected. DSOL tokens not deposited in Drift, including assets staked to the Drift validator, are unaffected. Insurance fund assets are being withdrawn and safeguarded. The protocol has been frozen, and the compromised wallet has been removed from the multisig.

Advertisement

As such, this is the third major exploit in recent months that did not involve a code vulnerability. Social engineering and operational security failures, rather than smart contract bugs, are increasingly how money leaves DeFi protocols.

The durable nonce vector is particularly dangerous because it exploits a feature that exists for good reason and is difficult to defend against without fundamentally changing how multisig approvals work on Solana.

The open question, which Drift’s forthcoming detailed postmortem will need to answer, is how two separate multisig members approved transactions they did not understand, and whether any tooling or interface changes could have flagged durable nonce transactions as requiring additional scrutiny.

Read more: North Koreans hackers likely behind $286 million Drift Protocol exploit

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Trump Just Signaled Military Escalation Against Iran and Bitcoin Price Dropped 6% in Hours: Is $60,000 Next?

Published

on

Trump Just Signaled Military Escalation Against Iran and Bitcoin Price Dropped 6% in Hours: Is $60,000 Next?

Bitcoin price dropped to approximately $66,500, shedding nearly 6% in hours, after President Trump’s April 1st address signaled harder military strikes against Iran in the coming weeks, shattering the fragile optimism that had briefly lifted risk assets.

The S&P 500 followed into the red, with MSCI’s Asia Pacific index reversing a prior session’s rebound to fall 1.7%. Brent crude jumped more than 5% to above $106 a barrel as traders priced in prolonged Strait of Hormuz disruption. This market fallout is precisely the macro fog that keeps risk assets pinned.

Trump’s remarks reversed sentiment that had built earlier this week when he indicated a willingness to end the conflict before reopening the Strait of Hormuz, a critical global trade waterway.

The April 1st address walked that back entirely, using language that pointed toward escalation rather than negotiation. Investors received no timeline for resolution – only the prospect of intensified operations.

Advertisement

Bitcoin’s digital gold narrative took another hit. With the 30-day rolling BTC-to-S&P 500 correlation spiking to 0.75 – its highest in months – institutional desks are treating Bitcoin as a high-beta tech proxy, not a geopolitical hedge. The safe-haven narrative is cracking.

Discover: The best crypto to diversify your portfolio during market turbulence

Bitcoin Price Prediction: Hold $65,000 Support or Another Leg Down?

Advertisement

BTC is sitting at $66,500, stuck in a pattern of lower highs since the March peak at $76,000, with each recovery attempt getting weaker and selling pressure capping every bounce before it gets going.

The $64,000 to $65,000 floor is the level that matters most right now, it has held on multiple tests but a clean break below it opens the path straight back to $60,000 where the February wick bottomed out.

Source: BTCUSD / Tradingview

On the upside, $68,000 and then $70,000 are the levels that need to flip for any real recovery narrative to rebuild, and neither looks easy given how heavy every bounce has been recently.

Until one of those scenarios plays out, this is a chart in damage control mode.

The broader bearish trend in BTC’s recent price history makes this inflection point more consequential than it might otherwise appear.

Advertisement

Bitcoin ended March up just 2%, snapping a five-month losing streak – but it remains down roughly 45% from its October peak above $126,000. Apparent demand was already negative by approximately 63,000 BTC as of late last month, per CryptoQuant.

“Stock and commodity markets continue to whipsaw according to Trump’s latest comments on geopolitical developments,” said Caroline Mauron, co-founder of Orbit Markets.

“Bitcoin is largely following stocks’ direction, though in the past few weeks it has showed reduced sensitivity to both good and bad news.” That reduced sensitivity may be the one thin positive – but it hasn’t prevented a $6,500 drop in a single session.

Tether Gold (XAUT)
24h7d30d1yAll time

Notably, gold’s worst monthly performance in 17 years through March – down more than 11% – strips away the easy ‘rotate to safe havens’ narrative. Treasuries and cash are absorbing the flight-to-safety flow instead.

Advertisement

The 10-year U.S. Treasury yield surged as markets priced in persistent inflation driven by energy supply disruptions, creating a direct headwind for non-yielding assets like Bitcoin. Until the Iran situation resolves cleanly in either direction, Bitcoin is unlikely to decouple.

Explore: The best pre-launch token sales with asymmetric upside potential

The post Trump Just Signaled Military Escalation Against Iran and Bitcoin Price Dropped 6% in Hours: Is $60,000 Next? appeared first on Cryptonews.

Advertisement

Source link

Continue Reading

Crypto World

X (Twitter) Targets Scams by Locking First-Time Crypto Posts

Published

on

X (formerly Twitter) is moving to automatically lock accounts that suddenly post about crypto for the first time, in a bid to curb a growing wave of hacks and scam promotions on the platform.

Product lead Nikita Bier said the system will flag accounts with no prior crypto activity that begin promoting tokens, triggering identity verification before further posts. 

The feature specifically targets a common attack pattern where hackers take over high-follower accounts and use them to push meme coins or phishing links.

The change reflects a broader crackdown on crypto-related spam, which has surged in recent months. 

Hacked accounts promoting tokens have become one of the most reliable scam vectors on X, often exploiting audience trust to drive quick liquidity before disappearing.

Advertisement

In practice, the update treats sudden crypto activity as suspicious by default. That could reduce large-scale phishing campaigns but may also catch legitimate users posting about crypto for the first time.

Reaction has been split. Some users see it as a necessary step to clean up “crypto Twitter” and protect users from scams. 

Others argue it introduces excessive control, raising concerns about censorship and how platforms define “normal” behavior.

The post X (Twitter) Targets Scams by Locking First-Time Crypto Posts appeared first on BeInCrypto.

Source link

Advertisement
Continue Reading

Crypto World

Ethereum Price Prediction: Pepeto Raises Above $8.1M While ETH Drops Below $2,100 and SOL Faces Pressure

Published

on

Ethereum Price Prediction: Pepeto Raises Above $8.1M While ETH Drops Below $2,100 and SOL Faces Pressure

Google just warned that quantum computers could crack Bitcoin’s encryption in roughly nine minutes, a finding that rattled the crypto market this week. Ethereum and Solana are both losing ground for different reasons, and the ethereum price prediction shows limited recovery while traders weigh growing risks.

The real question is where smart money goes while the large caps stall. Pepeto has raised above $8.1M in presale, the Binance listing is approaching, and the entry available now is the asymmetric chance that large cap yields will never produce.

Google’s Quantum AI team published research showing that cracking crypto’s core encryption could need fewer than 500,000 qubits, far below earlier estimates, according to Bloomberg.

CoinDesk reported that roughly 6.9 million Bitcoin sit in wallets where public keys are already exposed. The findings do not mean an attack is imminent, but they tighten the timeline enough to change how traders think about where to put capital.

Advertisement

Top 3 Cryptocurrencies Amidst the Ethereum Price Prediction

Pepeto

Google just proved that quantum threats are closer than anyone assumed, and the traders paying attention are repositioning now. Most will stay frozen, waiting for large caps to recover. The ones looking at Pepeto see what has not been priced in yet.

That is the difference that separates early movers from everyone else. Most people who missed the early stages of the biggest crypto runs did not have the right tools when it mattered, and by the time a breakout became obvious the entry that counted was gone.

Pepeto exists to close that gap. The cross chain bridge moves your holdings between blockchains so you are never trapped on one network when the opportunity lives on another. The zero fee swap engine trades any token pair across every major chain at zero cost, which means your position never gets eaten by fees while you try to grow it.

While the ethereum price prediction keeps pointing to limited recovery, Pepeto’s exchange tools are already live and working from entry to exit. The mind who built the first Pepe token is part of the dev team, and a former Binance expert leads alongside. At $0.000000186, the presale price is a fraction of what any buyer will pay once the Binance listing opens. A $25,000 position earns 189% APY through staking, putting $49,000 in yearly returns into your wallet just for holding while the listing approaches.

Advertisement

That is the kind of return no large cap can produce from its current level. The presale is filling with serious capital, the Binance listing date is not moving backward, and the wallets that are not inside yet are running out of runway.

Ethereum

Ethereum is trading near $2,054 after a brief climb to $2,200 failed to hold, and the token remains down nearly 50% from its record high according to CoinMarketCap.

The Glamsterdam upgrade expected in June is the main catalyst, but derivatives still show heavy leverage that could trigger sharp moves. Even a push back to $2,400 delivers a modest return compared to the entries presale wallets are collecting before listing day.

Solana

Solana dropped to $79 after the Drift Protocol exploit drained $285 million from the network’s largest DeFi exchange according to Bloomberg.

Advertisement

SOL recovered slightly but the damage to confidence is fresh. Even a reclaim of $100 delivers less than 20% from here, which barely registers against the kind of early entry presale tokens offer before they hit the open market.

The Bottom Line

The ethereum price prediction turned cautious after ETH failed to hold $2,200 and Solana took a direct hit from the Drift exploit. Even the Google quantum research that rattled the market did not change the fact that large caps have limited room from here. Capital always flows to the sharpest entry, and right now that flow is headed into Pepeto.

The presale is above $8.1M, whales are entering with real size, and the Binance listing is locked in, which you can verify at the Pepeto official website. The wallets that miss this window will spend the next cycle wishing they had moved faster.

Click To Visit Pepeto Website To Enter The Presale

Advertisement

FAQs

What does the latest ethereum price prediction reveal after ETH pulled back from $2,200?

The ethereum price prediction shows ETH stuck below $2,200 with heavy leverage in derivatives, making a clean breakout difficult to call right now.

What is the ETH price forecast as geopolitical volatility and DeFi exploits shake confidence?

The ETH price forecast remains cautious because macro pressure and the Drift Protocol fallout are keeping risk appetite low across the market.

Advertisement

What does the latest ethereum market news mean for investors seeking better early stage opportunities?

Ethereum market news highlights limited large cap returns, pushing investors toward early presale entries like Pepeto that carry far bigger potential before the Binance listing, and all details are at the Pepeto official website.


Disclaimer: This is a Press Release provided by a third party who is responsible for the content. Please conduct your own research before taking any action based on the content.

Source link

Advertisement
Continue Reading

Crypto World

BTC Price Trades at $66K With 44% of Supply Now in the Red

Published

on

Cryptocurrencies, Bitcoin Price, Markets, Price Analysis, Market Analysis

Bitcoin (BTC) traded at $66,450 on Thursday, a 47% drawdown from its all-time high of $126,000 reached in October 2025. As a result, many BTC holders are sitting on significant unrealized losses, underscoring the risks still facing Bitcoin investors at current levels. 

Key takeaways:

  • Bitcoin’s 47% drawdown from its $126,000 all-time high has left holders with nearly $600 billion in unrealized losses.

  • Apparent demand and buying from US investors remain in deep contraction, suggesting broader market distribution. 

44% of Bitcoin circulating supply now in the red

BTC/USD trades 24% below its yearly open of $87,500 after it closed 2025 in the red. The prolonged weakness has pushed a significant portion of its supply underwater.

As Bitcoin trades at $66,450 on Thursday, roughly 8.8 million BTC are held at a loss, representing $598.7 billion in unrealized losses, or more than 44% of the circulating supply, according to data from Glassnode.

Advertisement

Related: Bitcoin risks new lows as US dollar targets highest level since April 2025

The magnitude of this figure implies a “structural resemblance to conditions observed in Q2 2022,” Glassnode said in its latest Week On-chain newsletter.

Glassnode explained that the 2022 bear market provides a precedent when roughly 3 million BTC needed to be redistributed before the market could recover. 

“Historically, resolving a supply overhang of this scale has required a meaningful redistribution of coins from loss-realizing holders to new buyers at lower prices.”

Cryptocurrencies, Bitcoin Price, Markets, Price Analysis, Market Analysis
BTC: Total supply in loss. Source: Glassnode

This mounting paper loss has eroded conviction, prompting long-term holders (LTH) to capitulate by selling below their cost basis.

LTH realized loss, a metric that  measures the aggregate dollar value of Bitcoin sold at a loss by investors who have held BTC for more than 155 days, has risen to $200 million, “confirming active capitulation,” Glassnode said, adding:

Advertisement

“A meaningful cooldown toward levels below $25M per day would represent a more compelling signal of exhaustion in selling pressure, and a prerequisite for the base formation that historically precedes a sustainable bull market transition.” 

Bitcoin LTH realized loss. Source: Glassnode

BTC’s spot price is also below the average cost basis of US spot Bitcoin ETF holders, currently at $83,408, suggesting that these investors are increasingly under strain.

US spot Bitcoin ETF cost basis chart. Source: Glassnode

The risk-off sentiment is also seen in global Bitcoin investment products, which recorded more than $194 million in net outflows during the week ending March 27.

Bitcoin apparent demand contraction persists

Bitcoin’s apparent demand has stayed negative since mid-December 2025, as traders and investors continue to be risk-off amid BTC’s price weakness.

Capriole Investment’s Bitcoin Apparent Demand metric shows that the demand for Bitcoin is at -1,623 BTC on Thursday, and that sellers are in control.

Bitcoin apparent demand. Source: Capriole Investments.

The continued contraction in total apparent demand indicates persistent “selling from retail,” CryptoQuant said in its latest Weekly Crypto report, adding:

“The sustained demand contraction, now persisting since late November 2025, confirms that the broader market remains in distribution.”

Meanwhile, Bitcoin’s Coinbase Premium Index, which measures the difference in pricing between the BTC/USD pair on Coinbase and Binance, also remains in negative territory.

“The persistent negative premium indicates that US investors have not yet re-entered the market at scale,” CryptoQuant said, adding:

Advertisement

“This is consistent with the demand contraction seen across on-chain metrics.”

Bitcoin Coinbase Premium Index. Source: CryptoQuant

As Cointelegraph reported, Bitcoin price risks new lows in the short term amid a strengthening US dollar.