Drift Protocol Hack: Durable Nonces, Admin Capture, and the $250M+ Solana Drain
A forensic reconstruction of how a Solana perpetuals venue appears to have been captured through privileged approvals, delayed execution, and state reconfiguration rather than a generic trading-engine bug.
The $250M Drift Hack: Step by Step
Watch each phase of the exploit unfold. Click any node or step indicator to jump directly to that phase.
TL;DR
-
The strongest evidence supports an administrative capture, not a public smart contract bug.
-
Drift said the attacker used a durable-nonce-based attack to take over Security Council administrative powers.
-
The clearest exact artifact is a small pre-attack withdrawal from Drift Vault to the attacker wallet, which looks like rehearsal.
-
The
CVTtheory still fits, but best as a monetization layer after privileged control was already captured. -
The operational lesson is simple: if admin state controls collateral, oracle trust, and withdrawals, admin workflow is part of protocol security.
Four moves explain the incident
The shortest useful model is capture trust, delay execution, reconfigure policy, then extract value.
Capture approvals
Signer trust appears to have been compromised before the visible drain began.
Use durable nonces
Signed transactions could wait for the attacker's preferred execution window.
Reconfigure state
Collateral policy, oracle trust, and withdrawal protections became attacker-controlled surfaces.
Bridge out fast
The reported exit route was Solana swaps, Circle CCTP, then Ethereum-side consolidation.
What Is Actually Confirmed
The public record is noisy, but the core facts are not.
Drift said a malicious actor used a durable-nonce-based attack to gain unauthorized administrative access. That matters because Drift's critical controls are not only in trading logic. They also live in privileged state transitions: collateral admission, oracle configuration, market status, exchange status, and withdrawal guards.
If that admin path is captured, the attacker does not need to bypass the system. They can change what the system trusts.
How the attack likely moved through Drift's control surface
This version treats the exploit as a staged control-system takeover: trust is captured first, delayed execution preserves timing, then privileged state changes turn policy into an extraction path.
Capture signer trust
Approvals are obtained or disguised before any visible drain begins.
Signer workflow capture
The attacker gains signed authority without needing to break the public trading engine.
Preserve the window
Durable nonces split approval time from execution time.
Durable nonce window
Signed payloads remain live long enough for the attacker to choose the cleanest moment to strike.
Take privileged control
This is the pivot: the protocol starts trusting attacker-chosen state.
Security Council admin powers
At this point the attacker no longer bypasses defenses. They redefine the defenses.
Price inputs and accepted feeds can change.
Borrow power and asset usefulness can be reshaped.
Limits, pauses, and gatekeeping can be weakened.
Drain and bridge out
Once policy bends, normal rails become the exit route.
Vault drain and bridge-out
Withdrawals, swaps, Circle CCTP, and Ethereum-side consolidation become the visible part of the attack.
Why this looks like privileged capture, not a normal DeFi bug
The critical distinction is whether the attacker exploited a public entry point or first gained the authority to change what the protocol accepts as safe.
- A public code path is flawed.
- Any user can hit it directly.
- Funds leave through the broken entry point.
- Privileged approval flow is captured.
- Durable nonces preserve delayed execution.
- Admin-only state changes land before the drain.
The Durable Nonce Angle
Durable nonces are not the bug. They are the scheduling layer that made the attack harder to detect.
Normal Solana transactions expire quickly because they rely on recent blockhashes. Durable nonce transactions can be signed earlier and executed later. In a governance or council workflow, that means the approval moment and the execution moment can be separated by days or weeks.
The dangerous property is delayed execution
When privileged transactions stop expiring quickly, social engineering and delayed execution become much more dangerous.
Normal Solana transaction
Approval and execution stay on nearly the same clock.
Durable nonce transaction
The attacker gets to choose timing after signatures already exist.
Attack Breakdown
The most defensible reconstruction is not complicated.
The likely sequence
The best-supported path is capture authority, reshape trust, then monetize.
Capture signer context
Approvals are obtained or misrepresented.
Stage nonce payloads
Transactions remain executable later.
Execute admin instructions
Privileged state transitions land first.
Alter trust assumptions
Collateral or oracle policy becomes attacker-friendly.
Withdraw real assets
Vault value becomes reachable under the manipulated state.
Swap and bridge out
Funds move off-route before containment catches up.
The clearest early proof: a rehearsal withdrawal
The strongest exact artifact recovered in this investigation is transaction:
5brWcBQk4iYGH1YuaA4JYS6QhedA9itA2MDaJixqrhQe9Pk6mzpt2N68Ne5a2nqrgHmg5AxN4RMPH3paqX5jSM8a
Solscan labels it as a withdrawal from Drift Vault JCNCMFXo5M5qwUPg2Utu1u6YWp3MbygxqBsBeXXJfrw to Drift Exploiter 1 HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES.
The amount was only 0.03000003 WSOL, but that is exactly why it matters. It reads like a test of the extraction path before the main drain.
Drift's own wording sets the frame
Drift described the incident as a durable-nonce-based attack that rapidly took over Security Council administrative powers.
Open Drift's official statementSmall WSOL withdrawal from Drift Vault to attacker
This is the cleanest direct pre-drain proof artifact recovered in the case.
Open the exact Solscan transactionWhy admin capture mattered more than any single downstream trick
Once privileged execution is lost, multiple safety layers become exploitable at once.
One privileged path can reshape the whole risk model
Admin capture matters because it converts multiple downstream trust surfaces into attacker-controlled levers.
Admin capture
Security Council or equivalent control path is abused.
Oracle trust
Which prices the protocol accepts can change.
Collateral policy
Asset weights and usefulness can shift.
Withdrawal guards
Limits and pause controls become weaker.
Real asset extraction
The drain happens after the policy layer is already bent.
This is why "admin takeover" is the main story. Oracle abuse or fake collateral may have been part of monetization, but they are downstream once the attacker can change trusted state.
Where the CVT theory fits
r0bre's three-transaction claim is still useful:
-
create a Drift user account
-
deposit
500 million CVTas collateral -
withdraw real assets against that collateral
That is a plausible monetization path because Drift's cross-collateral model explicitly turns approved deposits into usable margin according to policy. But the CVT story does not explain the root cause by itself. The more important question is how the protocol could have been made to trust that asset in the first place.
The best current answer is privileged reconfiguration after admin compromise.
Evidence Map
Exact artifacts versus strong reported leads
41 million JLP at about $155 millionSolana swaps -> CCTP -> EthereumThree abbreviated hashes still matter, but only as leads
These shortened signatures come from public investigator threads. The full Solscan transaction IDs were not published, so they cannot be independently opened and should be treated as directional clues rather than exact evidence artifacts.
Pre-attack test withdraw
Exact and verified5brWcBQk4iYGH1YuaA4JYS6QhedA9itA2MDaJixqrhQe9Pk6mzpt2N68Ne5a2nqrgHmg5AxN4RMPH3paqX5jSM8a
The one fully published transaction in the trail: a small rehearsal withdrawal from Drift Vault to the attacker wallet.
Alleged user account creation
Thread-only hash4xzb1AXSw45...
Reported in public threads as the setup transaction that created a Drift user account before the rest of the sequence.
Alleged 500M CVT deposit
Thread-only hash5V72ZK1WejP...
Cited as the abbreviated signature for the claimed oversized CVT collateral deposit used in the monetization theory.
Alleged real-asset withdrawal
Thread-only hash2jCAE2SakEH...
Referenced as the shortened signature for the alleged withdrawal that turned the collateral story into real extracted value.
Fund Flow
The exit path is less disputed than the setup.
Where the funds appear to have gone
Investigators broadly agree on the route even where they differ on root cause details.
Drift vault outflows
Compromised protocol state makes real vault assets withdrawable.
Solana-side swaps
Assets are routed into more liquid exit assets before the bridge leg.
USDC concentration
Bridge-friendly value is assembled before leaving Solana.
Circle CCTP
Funds move through the clearest publicly reported settlement rail.
Ethereum consolidation
Containment shifts from protocol response to broader ecosystem response.
ZachXBT's main contribution here is containment analysis. The key operational criticism is that funds were still moving in size during U.S. business hours without fast enough intervention across the bridge and issuer surface.
Timeline
A staged operation, not a single transaction burst
Confirmed items and plausible items are separated so evidence quality stays obvious.
Preparation phase
Drift later described a multi-week staged operation consistent with delayed privileged execution.
Nonce-account setup is alleged
Third-party reports say four nonce accounts were created. The fit is strong, but the public proof is still incomplete.
WSOL rehearsal withdrawal lands
The exact rehearsal withdrawal shows the extraction path was already working.
First major drain is reported
Decrypt reports roughly 41 million JLP, around $155 million, leaving the protocol.
Drift pauses deposits and withdrawals
The protocol acknowledges the incident publicly and moves into response mode.
Swaps, bridging, and consolidation continue
The case becomes a containment problem across Solana, Circle CCTP, and Ethereum.
Compact event register
Badges describe evidence quality, not importance: Confirmed means directly observable or officially disclosed, while Reported lead means the claim fits the public record but still lacks complete proof.
$155 million.Root Cause and Lessons
The root cause was privileged-state compromise.
That phrasing is more useful than "oracle exploit" and more precise than "admin key leak." Drift's published design makes collateral policy, oracle trust, and withdrawal safety dependent on trusted administration. Once that administration is captured, monetization paths multiply.
Three lessons follow:
-
Multisig thresholds are not enough if signers can approve opaque or delayed payloads.
-
Governance safety is protocol safety when admin state controls borrow power and withdrawals.
-
Durable nonce workflows need visibility and alerting, not just permissioning.
{
"title": "π¬ Admin capture to drain, and how a timelock breaks it",
"stage": { "width": 920, "height": 440 },
"nodes": [
{ "id": "attacker", "label": "Attacker", "role": "captures admin", "emoji": "π§βπ»", "x": 60, "y": 200, "color": "red" },
{ "id": "council", "label": "Security Council", "role": "admin powers", "emoji": "π‘οΈ", "x": 430, "y": 60, "color": "cyan" },
{ "id": "vault", "label": "Drift Vault", "role": "collateral control", "emoji": "π¦", "x": 430, "y": 330, "color": "gold" },
{ "id": "exit", "label": "Exit route", "role": "swaps β CCTP β ETH", "emoji": "π", "x": 760, "y": 200, "color": "purple" }
],
"links": [
{ "from": "attacker", "to": "council" },
{ "from": "council", "to": "vault" },
{ "from": "vault", "to": "attacker" },
{ "from": "attacker", "to": "exit" }
],
"nets": [
{ "id": "vault", "label": "Vault value" },
{ "id": "atk", "label": "Attacker (off-route)" }
],
"legend": [
{ "cls": "call", "label": "admin instruction" },
{ "cls": "token", "label": "asset movement" },
{ "cls": "sig", "label": "trust / state change" },
{ "cls": "fail", "label": "delayed / blocked" }
],
"scenarios": {
"What appears to have happened": [
{ "note": "Collateral policy, oracle trust, and withdrawals depend on <b>trusted administration</b> by the Security Council.", "hi": ["council","vault"], "bal": { "vault": "collateral intact", "council": "trusted" }, "net": { "vault": "$250M+", "atk": "$0" } },
{ "note": "The attacker captures Security Council admin powers through the reported durable-nonce takeover.", "tone": "bad", "hi": ["attacker","council"], "chip": { "from": "attacker", "to": "council", "label": "capture admin", "cls": "sig" }, "bal": { "council": "attacker-controlled" } },
{ "note": "With <b>durable nonces</b>, signed admin instructions stay executable until the attacker's chosen window.", "tone": "bad", "hi": ["council","vault"], "chip": { "from": "council", "to": "vault", "label": "durable-nonce admin tx", "cls": "call" } },
{ "note": "A tiny rehearsal withdrawal (<b>0.03 WSOL</b>) tests the extraction path from the vault to the attacker.", "tone": "bad", "hi": ["vault","attacker"], "chip": { "from": "vault", "to": "attacker", "label": "rehearsal: 0.03 WSOL", "cls": "token" } },
{ "note": "Once policy is attacker-friendly, the real vault assets become reachable and are drained.", "tone": "bad", "hi": ["vault","attacker"], "chip": { "from": "vault", "to": "attacker", "label": "drain $250M+", "cls": "token" }, "bal": { "vault": "drained", "attacker": "+$250M+" }, "net": { "vault": "$0", "atk": "+$250M+" } },
{ "note": "Funds are swapped on Solana, concentrated to USDC, and bridged out through CCTP before containment catches up.", "tone": "bad", "hi": ["attacker","exit"], "chip": { "from": "attacker", "to": "exit", "label": "swap β CCTP β ETH", "cls": "token" } }
],
"Fixed (timelock + guardian)": [
{ "note": "The same design routes admin instructions through a <b>timelock</b> with monitoring.", "hi": ["council","vault"], "bal": { "vault": "collateral intact", "council": "timelocked" }, "net": { "vault": "$250M+", "atk": "$0" } },
{ "note": "Even if signer trust is compromised, the captured admin powers can no longer act instantly.", "tone": "ok", "hi": ["attacker","council"], "chip": { "from": "attacker", "to": "council", "label": "capture admin", "cls": "sig" } },
{ "note": "The staged durable-nonce admin tx hits a <b>timelock delay</b>, queues publicly, and triggers monitoring.", "tone": "ok", "hi": ["council","vault"], "chip": { "from": "council", "to": "vault", "label": "β³ queued (timelock)", "cls": "fail" } },
{ "note": "During the delay, a guardian or pause path revokes the malicious change before reconfiguration lands.", "tone": "ok", "hi": ["council"], "chip": { "from": "council", "to": "council", "label": "guardian revokes", "cls": "sig" } },
{ "note": "Collateral, oracle trust, and withdrawals stay under honest policy. The vault is never made drainable.", "tone": "ok", "hi": ["vault"], "bal": { "vault": "collateral intact" }, "net": { "vault": "$250M+", "atk": "$0" } }
]
}
}
Conclusion
The cleanest summary is this: the attacker does not appear to have broken Drift's math first. The attacker appears to have gained the right to tell Drift what to trust.
That distinction matters. It moves the incident out of the narrow category of trading-engine bugs and into the much larger category of governance, signer, and privileged-workflow failure.
Further study:
Appendix: Confirmed Facts, Disputed Claims, and Unknowns
Confirmed Facts
-
Drift said the attacker gained unauthorized access through a durable-nonce-based takeover of administrative powers.
-
The attacker wallet was
HkGz4KmoZ7Zmk7HN6ndJ31UJ1qZ2qgwQxgVqQwovpZES. -
A labeled
Drift Vaultaccount sent a small exact WSOL withdrawal to that wallet before the larger drain. -
More than
$250 millionappears to have been lost. -
Post-exploit routing moved through Solana swaps and Circle CCTP toward Ethereum.
Disputed or Partially Verified Claims
-
The precise
CVTmint and its exact role in the monetization path. -
The exact number of compromised or deceived signers.
-
The full list and order of admin-level instructions executed after compromise.
-
The final ETH balance attributed to the exploiter.
Unknowns That Still Matter
-
Which exact signer workflow failed.
-
Whether the approvals were maliciously disguised, device-compromised, or both.
-
Whether any off-chain coordination or infrastructure compromise preceded the nonce phase.
Appendix: Sources
- Drift Protocol official statement
- ZachXBT on CCTP routing and response
- Only1temmy thread
- r0bre thread
- Omer Goldberg thread
- Lookonchain post-drain flow claim
- ArxsTV thread
- Decrypt reporting
- Drift protocol overview
- Drift cross-collateral deposits
- Drift oracle documentation
- Drift guard rails
- Solana durable nonce documentation
- Solscan pre-attack withdraw
- Solscan exploiter wallet
- Solscan Drift Vault