SlowMist: The multi-signature mechanism was modified more than a week before the Drift theft, followed by an administrator privilege leak.

robot
Abstract generation in progress

BlockBeats message, April 2, SlowMist posted an analysis of the Drift theft incident, pointing out that during the week before the attack, Drift adjusted its multisig mechanism to “2/5” (1 old signer + 4 new signers) and did not set a time lock (timelock). The attacker then obtained administrator privileges, forged CVT tokens, manipulated the oracle, disabled security mechanisms, and transferred high-value assets from the liquidity pool.

At present, the stolen funds have mostly been consolidated to Ethereum addresses, totaling about 105,969 ETH (about $226 million). SlowMist said that the related fund flows are still being continuously tracked.

DRIFT-40.31%
ETH-3.93%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments