DeFi platform Drift suspends deposits and withdrawals after crypto hack

Share This Post

DeFi platform Drift has suspended deposits and withdrawals after losing millions of dollars in a crypto hack.

Editorial

This content has been selected, created and edited by the Finextra editorial team based upon its relevance and interest to our community.

The firm posted on X that it was investigating ‘unusual activity’ on the protocol, telling users that it was not an April Fool’s joke.

Security researchers estimate losses at up to $240 million, blaming governance security as the chief vulnerability after the attcker infiltrated a multisig upgrade a week ago.

One independent researcher observed: “This isn’t a technical vulnerability, It’s a governance catastrophe. Drift’s smart contracts themselves were fine. The problem was:
• Multisig handoff process failure
• Handing the hacker a “master key”
• All subsequent operations were “legitimate” calls”

In summary: “The essence of the Drift hack = Unified Liquidity Pool (risk concentration) × Multisig Vulnerability (privilege loss) × Excessive Admin Privileges (no checks)”

“At the cost of $240 million, it sounds the alarm for the entire DeFi industry.”

Related Posts

BNY investments’ short-dated bond strategy tokenized by Bermuda-regulated OpenEden

OpenEden has introduced HYBOND, the first tokenized product tied...

Bitcoin heads into holiday weekend exposed as ETF and CME flows go offline

Bitcoin is trading choppily around $66,600, as the extended...

Bitcoin Stays Weak on Oil Woes as Analyst Queries Return to $10,000

Bitcoin (BTC) gained a $10,000 price warning as stocks...

Riot Platforms Sells 3,778 Bitcoin as Miners Eye Profitability Pressures

Bitcoin miner Riot Platforms sold 3,778 Bitcoin in the...

REAL and Redstone Collaborate to Enhance Data Integrity for Tokenized Assets – Blockchain Bitcoin News

Strategic Integration for Institutional Growth Blockchain infrastructure firm...