Slow Fog: The multi-signature mechanism was modified more than a week before Drift was stolen, and then the administrator privileges were leaked
The analysis of the Drift theft incident by Slow Fog pointed out that a week before the attack, Drift adjusted its multi-signature mechanism to "2/5" (1 old signer + 4 new signers) and did not set a timelock. The attacker then gained administrator privileges, forged CVT tokens, manipulated the oracle, disabled security mechanisms, and transferred high-value assets from the liquidity pool.
Currently, the stolen funds have mainly been aggregated to an Ethereum address, totaling approximately 105,969 ETH (about 226 million USD). Slow Fog stated that the flow of related funds is still being tracked.
You may also like

How much longer can Ethereum's last big buyer hold on?

The pricing controversy of Trade.xyz exposes the fatal weakness of Pre-IPO perpetual contracts

World Cup 2026 Coming – WEEX Celebrates with $1M Prize Pool & Michael Owen Live

Galaxy in-depth report: Is Solana still worth paying attention to?

Young people in South Korea make a "final effort" in the epic bull market

Dialogue with OmenX Founder: Why does the prediction market need an evolution from "spot" to "derivatives"?

When the P2P illicit funds from ten years ago turned into 60,000 bitcoins

Morning News | CME Group launches Nasdaq Cryptocurrency Index futures; Asset management giant Janus Henderson strategically invests in Ethena

Why did Oracle deliver the strongest financial report in history, yet its stock price fell?

Bitcoin Layer 2 Network Botanix: Why Did We Choose to Dissolve?

Morning Report | OpenAI has submitted an S-1 registration statement draft to the U.S. SEC; Morpho completes $175 million financing

Galaxy Deep Research Report: How Hyperliquid's HIP-4 Upgrade Changes the Landscape of Prediction Markets?

Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI

Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention

Every exchange is a "Universal Exchange."

The counterattack of traditional finance: Alliance chains are quietly reviving

Pantera Capital Partner: How Tokenization is Restructuring the Private Equity and Early Investment Ecosystem?

Mastercard Launches Agent Pay for AI, Plans to Record AI Agent Payment Authorizations on Polygon
Mastercard launched Agent Pay for AI, a new payment protocol designed to help AI agents make small payments such as pay-per-use access to data and APIs. The system plans to record human-granted AI agent permissions on Polygon, focusing on verifiable authorization, identity, and payment controls.
