Durable Nonce Phishing Attack Breaches Drift Admin Privileges by Professional Hacker Group

Durable Nonce Phishing Attack Breaches Drift Admin Privileges by Professional Hacker Group

N
News Editor 01
2026-07-10 11:13:13
A sophisticated phishing attack exploiting durable nonce pre-signatures has compromised Drift's on-chain admin privileges. The technique, active for over two years, was executed by a professional hacker group, causing DRIFT token volatility.
durable noncephishing attackDrift protocolDeFi securityhacker

A new security vulnerability has shaken the DeFi sector. According to a report by CryptoComLearn, a sophisticated phishing attack exploiting a durable nonce mechanism has successfully breached the on-chain admin privileges of the Drift protocol. Attackers tricked users into signing offline pre-signed transactions that appeared legitimate, then used those signatures to execute malicious operations at any future point in time.

Attack Method: Durable Nonce Pre-Signature Phishing

The report highlights that this attack leverages the nonce mechanism in blockchain transactions. While traditional nonces prevent replay attacks, durable nonces allow attackers to obtain user signatures in advance and trigger transactions at any subsequent block height. By luring users through phishing websites or fake DApps to pre-sign transactions containing a durable nonce, the attackers could then modify contract parameters, transfer assets, or upgrade contracts after gaining control.

This technique has existed for at least two years, but this incident marks the first confirmed practical exploitation targeting the admin privileges of a decentralized exchange. Security experts note that since pre-signed transactions appear identical to normal authorizations on the user side, ordinary users are highly susceptible.

Professional Hacker Group Involved; DRIFT Surges

Analysis suggests the attack was orchestrated by a professional hacker group using multiple stealth tactics, including counterfeit front-end interfaces and social engineering to induce targets to sign specific messages. Notably, following the incident, Drift's native token DRIFT surged +33.54% in a short period, reflecting mixed market sentiment—ranging from panic buying to potential insider trading or market maker activity.

Broader DeFi Security Landscape

This attack is not an isolated case. Recent weeks have seen multiple major incidents in DeFi:

  • DeFi hacks have caused cumulative losses of $7.7 billion, while insurance payouts lag severely, exposing the industry's risk management shortcomings.
  • AI-driven blockchain attacks are on the rise and are projected to become a dominant threat by 2025, leveraging machine learning to automatically identify contract vulnerabilities and launch targeted phishing campaigns.
  • Ranger Finance has announced closure due to financial difficulties, becoming another casualty of the current bear market, with its platform assets facing liquidation risks.

Implications for Investors

Frequent security incidents remind all DeFi participants to never sign unverified transaction messages, especially those involving “pre-authorization” or “offline signing.” It is crucial to use audited protocols with transparent communities and to follow project security announcements closely. The dramatic price swings of DRIFT also suggest market manipulation risks, urging investors to remain vigilant.

As of now, the Drift team has not issued a detailed official response but has temporarily suspended some contract functions. The security community is closely monitoring hacker addresses in an attempt to recover stolen assets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.