Drift Hit by Hack After Multisig Reconfiguration and Admin Access Compromise
ChainCatcher reports that blockchain security firm SlowMist has released a postmortem on the Drift exploit. According to the analysis, Drift altered its multisig arrangement a week before the incident, moving to a "2/5" setup—one existing signer alongside four new signers—without putting a timelock in place. SlowMist said the attacker later obtained administrative privileges, minted counterfeit CVT tokens, manipulated oracle data, shut down security safeguards, and drained high-value assets from the vault. The stolen funds have largely been consolidated into Ethereum addresses, totaling about 105,969 ETH, or roughly $226 million. SlowMist added that on-chain tracking of the funds remains ongoing.