Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

David Hoffman

👤 Speaker
2256 total appearances

Appearances Over Time

Podcast Appearances

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

So again, it took two of five on this multisig in order to have this kind of god mode ability to drain 285 million, which is 50% of Drift's TVL.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

And it was a very sophisticated group that pulled this off.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

So someone like the Lazarus group, maybe even Indeed was them.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

I'm not sure.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

I haven't seen kind of the reporting on this.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

And that was the vulnerability.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

So they were able to trick two of Drift's five multi-sig signers to sign these transactions that they didn't fully understand.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

And that's how this hack happened.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

Unfortunately for users, the money's gone, right?

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

So Drift hasn't come out with a way to remunerate users.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

Drift was not a huge perps protocol in the scheme of all perps protocols.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

They were kind of like top 30, but they were the biggest, I think, on Solana, at least one of the largest on Solana.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

And as you said, I mean, this ranks as one of the biggest hacks ever, certainly the largest on Solana.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

This reminded me a little bit of the Ronin sidechain hack.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

Do you remember 625 million?

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

That was in 2022.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

That was also a multi-sig type hack, social engineering, compromised keys.

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

Like these multi-sigs are, they are just hazardous for protocols to have in place, right?

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

And I mean, what are the lessons that we learned from this?

Bankless
ROLLUP: Google’s Quantum Warning | Trump’s Iran Speech | Ethereum Economic Zones | Drift Hack

Certainly, even if you have a multi-sig, there are better ways to design it.