Paul
18 posts


@DivergSec @DriftProtocol Thanks. That‘s honest and very telling . @DriftProtocol - who‘s on vacation and can you get hold of that employee?
English

Update on our investigation into @DriftProtocol:
We have concluded our investigation and shared all findings directly with the Drift team. There are certain areas and internal data points that are only accessible to them, which limited the scope of what we could independently verify.
Based on the information we provided, we believe there is sufficient evidence to help determine who was involved. However, without full access to all internal resources, we cannot definitively conclude this ourselves and can only form evidence-backed assumptions from on-chain data.
At the request of the Drift team, we are unable to disclose specific details of our findings.
We will continue to monitor the on-chain situation closely, and if anything new emerges, we will be on top of it.
We appreciate the opportunity to assist and thank the Drift team for their collaboration throughout this process.
We will continue improving our forensics capabilities and take on board all feedback from the community. We’ll also do our best to answer any questions within the limits of what we can share.
Thank you,
Diverg
English

@Just_2_Cool @DriftProtocol you aware of this and the recommendations to click links? Not legit i guess??
English
Paul retweetledi

Critical information of parties related to the exploit have been identified. Drift is now sending an on-chain message from 0x0934faC45f2883dd5906d09aCfFdb5D18aAdC105 to the ETH Wallets that holds the stolen funds.
Wallet 1: 0xAa843eD65C1f061F111B5289169731351c5e57C1 (Timestamp of message: Apr-03-2026 05:17:23 AM +UTC)
Wallet 2: 0xD3FEEd5DA83D8e8c449d6CB96ff1eb06ED1cF6C7 (Apr-03-2026 05:20:59 AM +UTC)
Wallet 3: 0xbDdAE987FEe930910fCC5aa403D5688fB440561B (Apr-03-2026 05:23:11 AM +UTC)
Wallet 4: 0x0FE3b6908318B1F630daa5B31B49a15fC5F6B674 (Apr-03-2026 05:25:11 AM +UTC)
We are ready to speak.
Please reach out via Blockscan chat.
To the community, Drift will share further updates as soon as third-party attributions are completed.
English

@spizzurp @DriftProtocol @futarddotio @metaproph3t it needs to be prevented that rest of tvl flows into hands of vcs and alleged investigation costs.. based on current status they should at first refund whats left on a pro rata basis. thats still almost half of everyone‘s deposit
English

@spizzurp @DriftProtocol @futarddotio @metaproph3t Its not only that the whole setup is ridiculous. I wouldn‘t have expected the secuirty standard to be so low (zero timelock). How is this responsible? Outflows of such amounts should require governance oversight. not possible if there is no time to verify decisions made.
English

Hear me out... If @DriftProtocol is:
(1) Unable to recoup stolen funds
(2) Reimburse depositors
All depositors impacted should band together and seek legal action.
Paying for lawyers via a @futarddotio raise. Would this be a fitting use-case for the platform? @metaproph3t
SPIZZIE@spizzurp
English

@spizzurp @DriftProtocol @futarddotio @metaproph3t Yes, i think thats way beyond what a user transferring funds can reasonably expect. pretty sure that even very conservative judges would agree to this, the only thing is that it does not help if the company is insolvent…
English

@NeelMacro @DriftProtocol Assuming the protocol would resume work. Isn‘t the most probable outcome a bank run of users to withdraw whatever is left? Who would continue trading with them? Does it make sense from a management perspective to continue after that?
English

@Mr_PDRs @DriftProtocol True, but think differently..
$Drift al ready erased near 40% of its mcap near, $18million in last two days..
Positive negotiation, will not only help to survive but also we will see new life for project.

English

@NeelMacro @DriftProtocol If they go silent, how to apply a law enforcement? , How to know the person behind this address ?
English

@NeelMacro @DriftProtocol fingers crossed. even 10-20 percent would be a hard-to-fill hole. thats 57 million, exceeding the initial vc investments.. but it would allow users to get at least a partial recovery of their funds i suspect..
English

#Drift Hack Update: Drift Protocol just made a major move.
They have identified the wallets holding the stolen funds.
Four Ethereum wallets. All pinged with on chain messages this morning between 5:17 AM and 5:25 AM UTC. Eight minutes. Four wallets. All contacted simultaneously.
This tells you two things.
- First Drift knows exactly who has the money. The exploit was not anonymous. Critical information about the parties involved has already been identified.
- Second they are opening a negotiation channel. The message says "We are ready to speak. Please reach out via Blockscan chat."
This is standard white hat protocol in DeFi. The team identifies the exploiter, contacts them on chain, and offers a negotiated return of funds. Usually in exchange for a bug bounty and no legal pursuit.
It has worked before. The Euler Finance hack in 2023 saw $197 million returned after exactly this kind of on chain negotiation.
The fact that Drift moved this fast means one of two things. Either this was a known vulnerability exploited by a white hat researcher. Or security firms tracked the funds faster than the exploiter expected.
$270 million is not easy to move or hide. Every bridge and exchange has been alerted. The exploiter knows this.
Watch for a response from those wallets. If funds start moving back the story ends well. If they go silent and try to bridge out this becomes a law enforcement matter.
The next 24 to 48 hours are decisive.
Follow @NeelMacro. The next move is already in the data.
Rest. #DYOR
English

@AlexArgow @StrategicHash @drift same. off the plan to hedge my 500 sol bag to 1000 sol over the course of the bear.. its all in drift as collateral
English

@StrategicHash The remaining funds are gonna get chopped up among lawyers and VCs. If you had less then a million on @Drift kiss that money goodbye. Was using drift to hedge my spot BTC and SOL positions and lost about 30% of my port yesterday. Sucks
English

UPDATE: @DriftProtocol exploiter has spent another ~2.46M $USDC to buy 1,195 ETH 2 hours ago, bringing total ETH bought to 130,262 ($266M).

English

@frank_thelen ja, das ist schon sinnvoll. kapitalerträge werden geringer besteuert als arbeitseinkommen und sind dann noch frei von sozialabgaben. Ok für sie, auch etwas für die Gesellschaft zu tun, Herr Thelen?
Deutsch

Ernsthafte Frage/Diskussion: Findet jemand den Vorschlag von Robert Habeck - Kapitalerträge mit Sozialabgaben zu versteuern - sinnvoll? Wie verrückt muss sein Programm werden? Oder wollen 15% einfach mehr Staat? #Politik #Bundestagswahl
Deutsch








