# Hack Related Articles

HTX News Center provides the latest articles and in-depth analysis on "Hack", covering market trends, project updates, tech developments, and regulatory policies in the crypto industry.

In-Depth Reconstruction of the $285 Million Drift Hack: How Should DeFi Governance Move Beyond "Amateur Hour"?

On April 1, 2026, Drift Protocol, the largest perpetual futures DEX on Solana, suffered a catastrophic hack resulting in a loss of $285 million. The attack, attributed to a sophisticated social engineering campaign rather than a technical exploit, unfolded over several months. Hackers first infiltrated Drift’s internal circles by posing as a legitimate market maker, building trust over time. They then exploited Solana’s "Durable Nonce" feature to trick core team members into blindly signing transactions that granted administrative control. A critical vulnerability was introduced when Drift migrated to a 2/5 multisig structure without a timelock, allowing instant execution of privileged transactions with just two signatures. The attackers finally triggered the attack by adding a fake token (CVT) to the whitelist, manipulating its oracle price, and using it as collateral to drain the protocol’s treasury. The incident highlights fundamental flaws in DeFi governance, including overreliance on multisig mechanisms that lack intent verification and are vulnerable to social engineering. It underscores the misalignment between retail-grade security tools and institutional-scale treasury management. The hack signals the need for a security paradigm shift in DeFi, including adoption of Hardware Security Modules (HSMs) for key management, intent-based policy engines for transaction validation, and professional third-party custody solutions to ensure institutional-grade safety.

marsbit04/13 12:00

In-Depth Reconstruction of the $285 Million Drift Hack: How Should DeFi Governance Move Beyond "Amateur Hour"?

marsbit04/13 12:00

1 Billion DOT Minted Out of Thin Air, Yet Hacker Only Made $230,000

On April 13, a security breach occurred involving the Polkadot bridge on the Ethereum network, where an attacker exploited a replay vulnerability in the MMR proof mechanism of Hyperbridge’s ISMP protocol. By reusing a historically valid proof and pairing it with a malicious request, the attacker bypassed verification and gained admin and minting rights over the wrapped DOT contract on Ethereum. They then minted 1 billion wrapped DOT tokens—2,805 times the existing supply—and attempted to liquidate them. However, due to extremely low liquidity in the wrapped DOT market, the massive sell-off crashed the token’s price by 99.98%, from $1.22 to approximately $0.000128. The attacker ultimately exchanged the tokens for only about 108.2 ETH (worth roughly $237,000), with gas costs as low as $0.74. The same exploit had been used previously in attacks on MANTA and CERE tokens, resulting in a total loss of around $242,000. Polkadot confirmed that the incident only affected DOT bridged via Hyperbridge to Ethereum and did not impact the native Polkadot network or DOT on other bridges. Exchanges including Upbit and Bithumb temporarily suspended DOT deposits and withdrawals as a precaution. The event highlights ongoing vulnerabilities in cross-chain infrastructure and the critical role of liquidity in limiting actual damages during large-scale exploits. It also reflects a broader trend of increasing DeFi security incidents in early 2026.

marsbit04/13 10:10

1 Billion DOT Minted Out of Thin Air, Yet Hacker Only Made $230,000

marsbit04/13 10:10

A $280 Million Lesson! The 2026 DeFi Security Guide to Avoiding Pitfalls

"DeFi Security Lessons from a $280M Hack: A 2026 Guide to Avoiding Pitfalls" The rapid growth of DeFi has turned it from a niche interest into a mainstream pursuit for high yields. However, this comes with significant risks, highlighted by a major attack on Solana's Drift Protocol in April 2026, resulting in losses between $220-$285 million. This event underscores that in DeFi, users bear full responsibility for their assets. Most losses occur during normal operations through common vulnerabilities: 1. **Excessive Token Approvals**: Granting unlimited contract permissions can lead to complete asset drainage. 2. **Phishing Websites**: Fake sites mimic legitimate projects to steal wallet credentials. 3. **Contract Exploits**: Code vulnerabilities allow hackers to legally drain funds. 4. **Rug Pulls**: Malicious projects withdraw liquidity, causing tokens to crash. The guide outlines five essential pre-interaction checks: 1. **Contract Security**: Verify contracts are open-source and audited by firms like CertiK. Avoid unaudited or newly deployed contracts. 2. **Authorization Management**: Avoid unlimited approvals; use minimal permissions and regularly revoke unused allowances via tools like revoke.cash. 3. **Official Access Points**: Bookmark official sites from trusted sources (e.g., project Twitter/Discord) to avoid phishing scams, which cause over 60% of losses. 4. **Abnormal Yields**: Extreme APYs (e.g., stablecoins >20%) often signal scams. Compare rates to established protocols like Aave. 5. **Asset Segregation**: Use a multi-wallet system (hot, DeFi, cold) to isolate assets and prevent total loss from a single breach. Additional risks include insider threats from developers or employees with privileged access. Psychological biases (e.g., FOMO) and AI-powered phishing make users susceptible. Core principles: never grant unlimited approvals, avoid unknown links, and diversify investments. Security is not optional but a fundamental requirement in DeFi.

marsbit04/08 00:06

A $280 Million Lesson! The 2026 DeFi Security Guide to Avoiding Pitfalls

marsbit04/08 00:06

活动图片