Drift Protocol Loses $270M After Solana’s Durable Nonce Feature Exploited

Drift Protocol Loses $270M After Solana’s Durable Nonce Feature Exploited

N
News Editor 01
2026-07-23 10:55:15
Drift Protocol lost $270 million after attackers exploited Solana's durable nonce feature. Pre-signed multi-sig transactions were broadcast weeks later, bypassing time limits. The largest loss was $155.6M in JPL tokens. Over $230M in USDC was moved to Ethereum via Circle's bridge.
Drift ProtocolSolanasecurity exploitDeFidurable nonce

Drift Protocol suffered a carefully orchestrated attack, losing approximately $270 million. The exploit centered on Solana's durable nonce feature, designed to allow transactions to remain valid indefinitely by storing a single-use code in a separate account. Attackers obtained valid multi-sig signatures from two council members in advance, then delayed broadcasting the pre-signed transactions for weeks.

Durable Nonce: A Double-Edged Sword on Solana

Solana normally uses blockhashes that expire in 60–90 seconds. Durable nonce removes this time constraint, making a transaction valid until the nonce is consumed. For multi-sig setups like Drift's five-member security council (requiring at least two signatures), this means once a signer approves, there is no easy way to revoke without manually updating the nonce account. Attackers exploited this inflexibility.

Attack Timeline: Pre-Signed Transactions and Delayed Broadcast

In the last week of March, the attackers created four durable nonce accounts—two linked to legitimate council members and two under their control. They secured signatures from two council members. When Drift's council roster changed on March 27, they adapted and collected new signatures. The breach began with a legitimate test withdrawal, followed by the broadcast of pre-signed transactions that hijacked admin rights and enabled unauthorized withdrawals. Funds were drained in two rapid transactions.

Tracking the $270M Stolen Assets

On-chain analyst ZachXBT traced the stolen funds. The largest portion was JPL tokens worth $155.6 million, followed by USDC stablecoins ($60.4M), CBBTC ($11.3M), and USDT ($5.65M), among others. The main operational wallet was funded via the NEAR Protocol eight days prior and remained dormant until the exploit. After the attack, assets were funneled through intermediary wallets on Backpack exchange, which requires KYC—a potential lead for investigators. ZachXBT noted that over $230 million in USDC was transferred to Ethereum using Circle’s cross-chain bridge. Circle faced criticism for failing to freeze the stolen funds within the first six hours.

The incident underscores human error in managing advanced multi-sig setups: post-signature monitoring was overlooked, and the durable nonce feature enabled delayed execution. Drift’s lending, treasury, and trading pools were affected, but DSOL deposits and assets staked with Drift’s validator remained safe.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.