Drift Protocol treasury drained; on-chain trail points to Backpack-linked funding and potential KYC lead
On-chain analyst Aryan (@_0xaryan) reported that Drift Protocol's treasury was recently emptied. The attacker address (HkG...ZES) first received funds via Near Intents eight days earlier, then stayed dormant for an extended period before abruptly pulling a large amount from the Drift treasury.
Tracking the outflows, the attacker split assets across multiple laundering addresses, including 8ub...Gxw. Those addresses were funded the day before the incident through the Backpack wallet. The launderers then used the cross-chain protocol Wormhole to move funds to an Ethereum address whose provenance traces back to Tornado Cash.
Backpack co-founder Armani Ferrante said the flow was not a direct "Backpack → Attacker" transfer, but an indirect path: "Backpack → Nonattacker (crosschain intent solver) → Attacker," adding that the relevant account holders have been verified.