u8
285 posts
















Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers. This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.

Looks like Drift was compromised by admin key compromise. Some speculation that maybe was tied to a dev w/ admin access locally doing a version bump on the Axios JS library, which was widely compromised yesterday 👇 Still fog of war... but would make sense


mcp+fcfs is a myth 🦄


Goonfi v2's WSOL/USDC pool is drained for about 250k likely due to a misconfig/bug in the program an hour ago. The program is now halted. solscan.io/tx/5A1YuYHff5R…


4/ These fairness guarantees are enforced by the protocol design and not dependent on trusted third parties or modified clients. SIMD will be available soon. Check out the Constellation website and read the full whitepaper: constellation.anza.xyz





Over the last 20 epochs, we tracked validator scheduling and block production behavior using shred data Now we’re making that data available on a revamped dashboard, along with a provisional scoring system




Atomic arbs that exclusively touch propAMMs now account for 5-10% of total arb revenue propAMMs put a lot of effort into fighting toxic flow. The ix sysvar lets them introspect the transaction to see exactly what other instructions are present, how the swap is being called, etc


