SlowMist's review of Drift Protocol theft: Lack of multi-signature security mechanisms was the main cause; DeFi project teams need to rehearse extreme scenarios.

robot
Abstract generation in progress

Deep Tide TechFlow message, April 02, according to the disclosure by MuteVigil founder Cos (Yúxián) (@evilcos), the root cause of the Drift Protocol theft incident was that one week earlier it migrated its multisig setup to a 2/5 configuration with no timelock (1 old signer + 4 new signers). Using this, the attacker took over admin privileges within a matter of hours. They then minted counterfeit CVT, manipulated the oracle, disabled related security mechanisms, and ultimately siphoned off all value assets in the pool, with losses exceeding $200 million.

Cos also called for all DeFi project teams to review, as soon as possible and on a regular basis, extreme risk scenarios after owner/admin private key compromise, and to improve alerting and response mechanisms; users should also clearly understand the exposure to potential losses of the DeFi protocol they participate in under extreme circumstances (such as internal malice), to avoid blindly entering the market.

DRIFT-40.31%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments