SlowMist's review of Drift Protocol theft: Lack of multi-signature security mechanisms was the main cause; DeFi project teams need to rehearse extreme scenarios.

robot
Abstract generation in progress

Deep Tide TechFlow message. On April 02, according to a disclosure by SlowMist founder Cos (Yu Xian) (@evilcos), the root cause of the Drift Protocol theft incident was that about a week earlier it migrated the multisig configuration to 2/5 without a timelock (1 old signer + 4 new signers). This allowed the attacker to take over admin privileges within a few hours. They then minted fake CVT coins, manipulated the Oracle, disabled related security mechanisms, and ultimately drained all value assets from the pool, with losses exceeding $200 million.

Cos also called for all DeFi project teams to review—promptly and on a regular basis—the extreme risk scenarios after owner/admin private key compromise, and to improve alerting and response mechanisms. Users should also clearly understand the loss exposure of the DeFi protocol they participate in under extreme circumstances (such as internal malicious activity), to avoid blindly entering the market.

DRIFT-26,3%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin