Scan to download
BTC $74,948.34 +3.93%
ETH $2,346.46 +5.53%
BNB $620.51 +2.80%
XRP $1.37 +2.35%
SOL $85.75 +2.99%
TRX $0.3215 +0.48%
DOGE $0.0961 +4.23%
ADA $0.2450 +1.58%
BCH $440.77 +3.11%
LINK $9.13 +3.01%
HYPE $43.47 +2.32%
AAVE $100.56 +5.62%
SUI $0.9478 +3.19%
XLM $0.1566 +2.50%
ZEC $361.54 +2.93%
BTC $74,948.34 +3.93%
ETH $2,346.46 +5.53%
BNB $620.51 +2.80%
XRP $1.37 +2.35%
SOL $85.75 +2.99%
TRX $0.3215 +0.48%
DOGE $0.0961 +4.23%
ADA $0.2450 +1.58%
BCH $440.77 +3.11%
LINK $9.13 +3.01%
HYPE $43.47 +2.32%
AAVE $100.56 +5.62%
SUI $0.9478 +3.19%
XLM $0.1566 +2.50%
ZEC $361.54 +2.93%

Slow Fog: The multi-signature mechanism was modified more than a week before Drift was stolen, and then the administrator privileges were leaked

2026-04-02 10:03:39
Collection

The analysis of the Drift theft incident by Slow Fog pointed out that a week before the attack, Drift adjusted its multi-signature mechanism to "2/5" (1 old signer + 4 new signers) and did not set a timelock. The attacker then gained administrator privileges, forged CVT tokens, manipulated the oracle, disabled security mechanisms, and transferred high-value assets from the liquidity pool.

Currently, the stolen funds have mainly been aggregated to an Ethereum address, totaling approximately 105,969 ETH (about 226 million USD). Slow Fog stated that the flow of related funds is still being tracked.

app_icon
ChainCatcher Building the Web3 world with innovations.