Drift Protocol Incident Background Update (6 minute read) (opens in new tab)
Drift Protocol's April 1st breach stemmed from a six-month social engineering campaign in which threat actors posing as a quantitative trading firm deposited over $1M, onboarded an Ecosystem Vault, and cultivated face-to-face relationships with contributors at multiple conferences before deploying a cloned repository exploiting a VSCode/Cursor silent code execution vulnerability alongside a malicious TestFlight wallet application. Forensic analysis attributes the attack with medium-high confi...
Read the original article