SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
Six-month social engineering campaign used Solana durable nonces, fake CVT collateral, and compromised contributor environments to drain $285M.
Loss
$285M
Risk
Ecosystem-level crisis
Confidence
96%
Reporter Agent synthesis with forensic confidence scoring
Attackers built trust with Drift contributors, compromised development workflows, staged a fake collateral token, and used pre-signed durable nonce transactions to silently transfer admin control before draining real assets within minutes.
High-privilege signing workflows lacked pre-execution intent verification, durable nonce safeguards, and strong signer counterparty validation.
confidence score
Ecosystem-level crisis
Attacker path, bridge transfers, token drains, mixer usage
Social engineering plus durable nonce pre-signature abuse
Dormant admin transactions could execute later without clear real-time signer awareness
Drift Security CouncilCVT collateral configMarket admin authorityBorrow limit controlsEmergency Bridge
Move funds off Solana
If your assets are at risk on Solana, bridge them to a safer chain immediately via LI.FI — the cross-chain aggregator covering 60+ chains and all major Solana bridges.
From (at risk)
Solana
Bridge to
Best Route via LI.FI
Solana → Ethereum
Mayan Swift • Across • Glacis aggregated
Est. Fee
~$0.50
60+ chains · gasless swaps on Solana · Jito bundles
60+
Chains
$2B+
Volume
20+
Bridges
Fall 2025
Threat actors pose as a legitimate quantitative trading firm and build relationships with Drift contributors.
Dec-Feb
A VSCode/Cursor exploit and malicious TestFlight wallet app are used to compromise contributor environments.
Mar 12
CarbonVote Token is deployed, wash-traded, and priced to appear usable as high-value collateral.
Apr 1
Pre-signed dormant transactions silently transfer admin control and approve CVT collateral limits.
Minutes
$285M in USDC, SOL, ETH, and JLP are withdrawn before protocol controls are frozen.
Demo X/Twitter integration for researcher posts, warnings, and fake-info checks
NullTrace links social posts to the incident by contract mentions, protocol name, researcher credibility, and fake-loss detection tags.
SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
NullTrace Intel
@nulltrace_ai · 4m
On-chain behavior and public reports are aligned. Confidence raised after wallet clusters matched the incident pattern.
Maya Chen
@maya_sec · 7m
The important signal is not only the drain. Watch the staging wallets and the small test transactions before the main move.
Rumor Watch
@intel_filter · 10m
Unverified recovery claims are circulating. No confirmed full recovery unless the protocol or tracked wallet flows support it.
suppressed by misinformation filter
SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
NullTrace Intel
@nulltrace_ai · 4m
On-chain behavior and public reports are aligned. Confidence raised after wallet clusters matched the incident pattern.
Maya Chen
@maya_sec · 7m
The important signal is not only the drain. Watch the staging wallets and the small test transactions before the main move.
Rumor Watch
@intel_filter · 10m
Unverified recovery claims are circulating. No confirmed full recovery unless the protocol or tracked wallet flows support it.
suppressed by misinformation filter
Generated incident narration for security leadership
briefing ready · 00:58 · analyst-grade summary