COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Drift Protocol loses $270 million after Solana’s durable nonce feature exploited
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > DeFi News > Drift Protocol loses $270 million after Solana’s durable nonce feature exploited
DeFi News

Drift Protocol loses $270 million after Solana’s durable nonce feature exploited

In Brief

  • Attackers exploited Solana’s durable nonce to make pre-approved Drift transactions weeks later.

  • Approximately $270 million in crypto assets was withdrawn and quickly dispersed to multiple wallets.

  • Human oversight, not a technical flaw, was at the core of this multi-signature security breach.

İlayda Peker
İlayda Peker 4 weeks ago
Share
SHARE

In a recent incident that differed noticeably from familiar cyberattacks, Drift Protocol suffered a significant loss, but not as a result of exploited bugs, stolen private keys, or the manipulation of oracles or flash loan tactics. Instead, attackers took advantage of Solana’s legitimate durable nonce feature to execute two previously signed transactions weeks after their approval by Drift’s multi-signature security council, catching the protocol off guard in an entirely new context.

Contents
What is durable nonce and how was it used?Course of the attack and asset tracing

What is durable nonce and how was it used?

On Solana, every transaction is typically sent with a unique blockhash that expires in about 60–90 seconds, a measure that prevents replay attacks and ensures the transaction’s freshness. However, Solana also offers a mechanism called the ‘durable nonce’, which allows transactions to rely on a single-use code stored in a separate account. This mechanism removes time constraints, enabling the transaction to remain valid indefinitely until the nonce is used. Durable nonce accounts are often intended as a security convenience for hardware wallets and enterprise custodians, helping to manage delayed transactions in a controlled way.

Yet, this flexibility has a downside: when attackers manage to get transactions pre-authorized, they can delay broadcasting them until weeks later. Once a signer approves a transaction, it can only be canceled if the nonce account is manually updated—a step often overlooked in everyday security routines.

Drift’s governance operates through a five-member security council, where every transaction requires signatures from at least two members. This multi-signature arrangement is a common defense in the decentralized finance sector, reducing the risk of a single compromised individual putting protocol funds in danger.

Course of the attack and asset tracing

In the last week of March, four durable nonce accounts were established. Two were genuinely associated with security council members, while the other two were under the attackers’ control. This enabled the attackers to secure valid signatures from two council members in advance. After a change in Drift’s council lineup on March 27, the attackers promptly adapted to the new structure, collecting the necessary signatures again.

The breach began with a legitimate test withdrawal from Drift’s insurance fund. Immediately after, attackers broadcast the pre-signed transactions to the Solana network—taking over administrative permissions and enabling themselves to create unauthorized withdrawal mechanisms. Funds were drained rapidly in two separate transactions.

Blockchain analysts identified that approximately $270 million worth of various cryptocurrencies was siphoned off to multiple wallets. The largest loss was in JPL tokens, amounting to $155.6 million, followed by $60.4 million in USDC stablecoins, $11.3 million in CBBTC, and $5.65 million in USDT, alongside numerous other digital assets.

The main operational wallet used in the attack had been funded eight days prior via the NEAR Protocol and remained inactive until it was mobilized for the exploit. Following the attack, assets were funneled to intermediary wallets established on the Backpack exchange, which requires identity verification—a detail that could offer investigators fresh leads.

On-chain analyst ZachXBT tracked the stolen funds, noting that over $230 million in USDC was transferred to Ethereum using Circle’s cross-chain bridging protocol. ZachXBT also highlighted that Circle, the company behind USDC, came under criticism for not freezing the stolen funds within the first six hours after the breach occurred.

The incident ultimately underscored human errors in managing advanced security setups like multi-signature accounts. The durable nonce feature facilitated the transaction broadcasts long after the initial approvals, exposing a major oversight in post-signature monitoring. Lending, treasury, and trading pools on Drift suffered losses, but DSOL deposits and assets staked with Drift’s validator were unaffected by the breach.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

RsETH hacked for $300 million, 116,500 tokens exploited

Kelp DAO hack exposes $300 million hole in rsETH

Aave raises $160 million after $200 million DeFi hack

Defi reels from $13 billion TVL drop after KelpDAO attack

Mythos AI exposes $1 billion risk in DeFi via DOT

İlayda Peker 2 April, 2026 - 6:52 pm 2 April, 2026 - 6:52 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
Uluslararası İlişkiler ve Siyaset Bilimi Mezunu, Kitap sever.
Previous Article Legal clash erupts after CFTC and DOJ challenge Illinois moves on crypto prediction markets
Next Article Bitcoin faces resistance as institutional demand offsets retail weakness, analysts say
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Ethereum holds at $2,335 with $5,600 as next target
Ethereum (ETH)
Dogecoin futures hit 15.36 billion tokens as price jumps 10 percent
Cryptocurrency News Dogecoin (DOGE)
Rakuten lets 44 million users convert points to XRP
Ripple (XRP)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?