Summary Points
- ZachXBT criticizes Circle for inaction during the $280M Drift Protocol exploit, calling them “asleep” as USDC was bridged across chains over several hours.
- The exploit was a sophisticated attack using durable nonces and social engineering, not a smart contract flaw, allowing the attacker to hijack administrative permissions quickly.
- Drift Protocol responded by freezing the asset, removing the compromised wallet, and working with authorities to trace stolen funds.
- Allegations highlight concerns over industry practices, with critics accusing Circle and Allaire of delays and inadequate response during major security incidents.
ZachXBT Criticizes Circle for Inaction During Drift Protocol Hack
Blockchain investigator ZachXBT has publicly criticized Circle, the issuer of USDC, for their delayed response during the recent Drift Protocol hack. The incident involved thefts totaling around $280 million. ZachXBT called Circle “asleep” as stolen USDC moved freely between blockchains.
During the multi-hour exploit, millions of USDC were bridged from Solana to Ethereum. ZachXBT pointed out that approximately 100 transactions took place while funds flowed, and no action was taken to stop them. He emphasized that “value was moved and nothing was done,” highlighting an apparent lack of oversight.
In a separate update, ZachXBT noted that the hacked funds were transferred as part of a coordinated effort. He also referenced a recent case where Circle froze over 16 business wallets, which he considers evidence of poor management. According to him, Circle and its CEO, Jeremy Allaire, showed “incompetent” handling of the situation and labeled them “bad actors” for the industry.
As discussions grow about how fast companies should act during such crises, many believe quicker responses could limit damage. The incident underscores the importance of vigilance and prompt action in blockchain security.
Meanwhile, Drift Protocol explained that the attack was highly sophisticated. The hackers used a “novel attack involving durable nonces” to execute pre-signed transactions. This method let them bypass real-time detection and control the protocol’s permissions quickly.
Drift said the attack was not due to a contract flaw or compromised seed phrases. Instead, the hackers used social engineering techniques to gain approval from the protocol’s multisig security. They triggered malicious transactions and removed withdrawal limits within minutes.
The timeline provided by Drift showed the attack’s planning started as early as March 23. The attacker created accounts linked to blockchain wallets, then continued preparing through late March. The final breach occurred on April 1, after executing pre-signed transactions that allowed access to the protocol’s admin functions.
After discovering the attack, Drift froze its remaining functions and removed the compromised wallet. The team has been working with security firms, exchanges, and law enforcement in hopes of recovering the stolen assets.
This incident highlights how advanced hacking techniques can exploit blockchain protocols. It also raises questions about the responsibility of stablecoin issuers like Circle to protect user funds. As technology evolves, the industry must stay vigilant to prevent similar exploits in the future.
Stay Ahead with the Latest Tech Trends
Learn how the Internet of Things (IoT) is transforming everyday life.
Discover archived knowledge and digital history on the Internet Archive.
Disclaimer
This content is for informational and entertainment purposes only and does not constitute financial or investment advice. Cryptocurrency is highly speculative and carries significant risk, including the potential loss of your entire investment. Do not make financial decisions based on this information. Consult a licensed financial advisor before investing. This site does not offer, sell, or advise on cryptocurrency, securities or other regulated financial products in compliance with SEC and applicable laws. Please do your own research and seek professional advise.
CryptoV1
