How Solana's Durable Nonces Enabled the $285M Drift Protocol Exploit
On April 1, 2026, Solana-based perpetuals protocol Drift suffered a $285 million loss after an attacker phished two of five members on its security council over several weeks. The attacker exploited Solana's durable nonce feature, which allows transactions to be signed well in advance and submitted at any chosen later time without expiring. Unlike standard Solana transactions — which become invalid after roughly 150 slots (about one minute) — durable nonce transactions remain valid indefinitely until the nonce account is advanced. The post-mortem concluded that authorization effectively occurred at the moment of signing, not execution, meaning the stolen signatures were sufficient to authorize the attack days or weeks later. While durable nonces serve legitimate purposes such as offline signing, multisig coordination, and scheduled payments, their ability to bypass the standard expiry window removes a key safety property that most users unknowingly rely on.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in