Drift Loses Over $270 Million as Multisig Shift a Week Earlier Draws Scrutiny

Drift Loses Over $270 Million as Multisig Shift a Week Earlier Draws Scrutiny

N
News Editor 01
2026-07-23 03:30:14
Drift Protocol lost more than $270 million in an attack on April 1. On-chain analysis points to a multisig migration completed a week earlier, with a 2-of-5 setup and zero timelock raising questions about governance and key control.
Drift ProtocolSolanamultisig wallethackon-chain security

Drift Protocol, a perpetual futures DEX on Solana, was hit on April 1, with treasury assets falling from $309 million to $41 million within minutes. More than $270 million was drained. The incident also triggered a sharp sell-off in the DRIFT token, which dropped from about $0.072 to $0.055, a decline of roughly 20% to 28%, while its market capitalization fell to $31.27 million.

According to the source material, this was the largest attack in the Solana ecosystem since the 2022 Wormhole exploit. The stolen assets included 41.72 million JLP worth about $155.6 million, 51.616 million USDC, 125,000 WSOL worth about $10.45 million, and 164,000 cbBTC worth about $11.29 million.

Funds bridged to Ethereum as attention turns to admin control

After the attack, the assets were bridged to Ethereum, where the attacker bought 19,913 ETH, valued at about $42.6 million, as part of fund dispersal and laundering activity. PeckShield founder Xuxian Jiang said the admin key behind Drift was “definitely leaked or compromised.” That comment pushed the focus toward privileged access rather than a routine smart contract flaw.

Omer Goldberg, founder of Aave risk adviser Chaos Labs, published a separate on-chain reconstruction. He said Drift moved the sharded private keys controlling the system about a week before the exploit and completed a multisig migration. The new multisig wallet was created by one of the signers from the old wallet, but that signer did not add themselves to the new setup. That detail stood out.

New wallet used a 2-of-5 threshold with a zero-second timelock

Goldberg’s analysis said an attacker also submitted a proposal in the old multisig to hand over admin control to the new wallet. The new multisig had 5 signers, but only 1 came from the previous setup. The other 4 were entirely new. The wallet was configured with a 2-of-5 signing threshold and a timelock of 0 seconds.

That meant transactions and permission changes could be executed immediately once the threshold was met. At the time of the exploit, the only signer in the new multisig who had remained from the old wallet submitted a proposal to transfer Drift’s admin authority. Just 1 second later, another signer in the new multisig approved it, satisfying the 2-of-5 requirement and completing the transfer.

Silent multisig migration fuels questions around internal controls

The sequence has led to broader questions from the community. One concern is that the incident may involve key exposure affecting at least two signers. Another centers on staff turnover. The source says core team members had left roughly a month before the attack, prompting scrutiny over whether key handover procedures during departures were handled securely and whether internal controls weakened during the transition.

The report also notes that Drift quietly migrated its multisig account to a new address a week before the attack, without public explanation and without going through community governance. The identities and backgrounds of the four new signers were not transparent. On-chain data also showed that the attacker sent 1 SOL to the attack wallet a week earlier and made a small test transfer worth just $2.52. Drift had not directly responded to those questions at the time covered by the source.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.