hackhack

20 posts

hackhack banner
hackhack

hackhack

@hackhackai

Hybrid human + AI Solana audits

Katılım Şubat 2026
29 Takip Edilen205 Takipçiler
hackhack retweetledi
r0bre | Accretion.xyz
How do Durable Nonces work? A solana transaction basically consists of a transaction message and the signatures. The transaction message is a list of instructions you want to call. For example, transfer 1 sol from A to B. When you sign a transaction, you attach a wallet's approval to that message. In this case, you'd let A sign, approving their transfer. Without their signature, the transaction would arrive at the validator node, and then be rejected because it needs a signature from A but doesn't have it. Now, what you usually don't want is that someone signs a transaction like a transfer, sends it through the internet towards the blockchain, but the packets never reach the blockchain nodes. So you send it again, and the second try works. But a few minutes later the original transaction ends up making it to the blockchain and now you've sent the transaction twice. For this and many other reasons, we must include a recent blockhash in our transactions. When a node receives your transaction it makes sure that it includes the hash of a block that was created within the last 150 blocks, which is 60 seconds on a 0.4s slot window. now, this 60s window can theoretically be a problem when the time between getting the latest blockhash, reviewing and signing a transaction and then sending it to the current leader takes more than that. It could take more time than that if you're slow with your hardware wallet signing process, and when you take your time validating every byte before signing it manually. That's why a workaround was introduced: Durable Nonces. Basically they allow you to submit transactions that were signed a long time ago. These transactions have to include a nonce in place of the blockhash, and they need to call the advance nonce system instruction so that the validator knows that theyre using a durable nonce (and the durable nonce gets updated). Now which one is gonna be a valid nonce? Well, we can set it up by creating a nonce account, and the nonce will be derived from the latest (real) blockhash and saved in this nonce account. What's interesting is that I can create nonce accounts for others, without their approval (which makes sense as if we'd needed their approval, this means they'd have to sign a transaction within the 60s window, defeating the nonce purpose). Another interesting thing is that the attacker fucked up a little. They created the nonce accounts for the victims from the start. This could have tipped of the victims -- why is there a nonce account for me suddenly? The attacked could have instead created nonce accounts for their own wallets (which generates the durable nonce), then make the victim sign for that durable nonce, and then change the nonce account authority from themselves to the victim before executing the pre-signed transaction! That's why I think that monitoring for nonce accounts in your name is not a silver bullet. It could have been in a different name and changed to your name a second before you're drained. What also becomes evident here is that the drift team likely used hardware wallets, and the capability the attacked had was only to get them to sign a malicious transaction. They didn't compromise keys directly. Using nonces was useful for the attacked because they removed time from the equation. If no nonces existed, the attacked would have to create a malicious proposal, get victim 1 to sign it, and then get victim 2 to sign it. Time would pass between those two signatures. Minutes, hours, maybe days. Even if the victims machines are compromised and on their computers the proposal would render as harmless, this time would introduce risk to the attacker where someone else could see the proposal, figure that its malicious, and flag it. A time lock on the multisig would have helped here, as it could have introduced that same time - detection risk to the attack. But a timelock itself would not have been enough -- it would have to be made sure that someone with an uncompromised computer actually checks out the transactions during that timelock period.
Drift@DriftProtocol

Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers. This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.

English
0
7
40
4.2K
hackhack retweetledi
r0bre | Accretion.xyz
Re Drift Hack, part 2 So now that we've established that we have an Admin/Multisig compromise on our hands, lets investigate further and try to figure out what keys of what multisigs were compromised when. First thread can be found here:
r0bre | Accretion.xyz tweet media
r0bre | Accretion.xyz@r0bre

Drift has been hacked. Lots of confusing information going around. I've taken a look at what's actually happening. The core attack sequence is just 3 transactions: 1. Create a new Drift User Account: solscan.io/tx/4xzb1AXSw45… 2. Deposit 500 Million "CVT" into Drift as collateral: solscan.io/tx/5V72ZK1WejP… 3. Withdraw Millions of real assets against the provided collateral: solscan.io/tx/2jCAE2SakEH… (and later transactions) Now, as it turns out, this CVT token was just created a few weeks ago. The core question: How did it become accepted collateral within Drift?

English
7
5
65
9.8K
hackhack retweetledi
r0bre | Accretion.xyz
Drift has been hacked. Lots of confusing information going around. I've taken a look at what's actually happening. The core attack sequence is just 3 transactions: 1. Create a new Drift User Account: solscan.io/tx/4xzb1AXSw45… 2. Deposit 500 Million "CVT" into Drift as collateral: solscan.io/tx/5V72ZK1WejP… 3. Withdraw Millions of real assets against the provided collateral: solscan.io/tx/2jCAE2SakEH… (and later transactions) Now, as it turns out, this CVT token was just created a few weeks ago. The core question: How did it become accepted collateral within Drift?
r0bre | Accretion.xyz tweet media
English
7
26
152
32.6K
Solana Stream
Solana Stream@solana_stream·
Demo Day at @mtndao wrapped up with 31 emerging teams showcasing innovations on @solana – from infra to AI, DeFi to consumer. Follow them for updates on their launches and progress! What stands out to you? 1. @SharkPoolSol – Education-focused stake pool 2. @pack3dotfun (@0x_twyla) – Unlock on-chain Packs 3. @hashishdotfun – Privacy-first PoW powered by @arcium 4. @anon0mesh – Off-Grid Private Freedom App on @arcium 5. @hackhackai – Hybrid human + AI Solana audits 6. @Living_IP – Powering Living Agents 7. @UpRockCom – DePIN network fueling AI 8. @_DASMAC_ – Onchain NASDAQ 9. @hydex_io – Hidentity for private transactions 10. @reflowxyz – Verifiable AI and compute 11. @unbrowse – Browser for agents at 10x cheaper cost 12. @GetPyra – World's first asset neobank 13. @axis_pizza – Create your own onchain ETFs 14. @blkw3_b – Frictionless gold ownership from $30 15. @stable_tweets – US mortgage market onchain 16. @GetRektApp – Trading as simple as a game 17. @stealf_finance – Privacy NeoBank 18. @attndotmarkets – Use Pump.fun creator fees in DeFi 19. @paystreamlabs – Democratizing institutional yields 20. @SP3NDdotshop – Buy Amazon with stablecoins 21. @avodotso – Marketplace for AI trading agents 22. @wesplit_io – Social protocol for group expenses 23. @aerosol_xyz – Utility for Solana communities 24. @looftaxyz – Rails between creators and revenue 25. @Xeno_Money – Stablecoin Native Card Network 26. @DefiMarkets – Fund Management OS 27. @AnterraGG – Onchain playground 28. @paggaapp – AI agents for business ops 29. @usetapestry – Open social graph (explore @zumichat) 30. @cheapnumbers@supersizegg real money games 31. @m3taversal – (Bonus: Living Agents pioneer) Recap: @solana_devs
Solana Stream tweet media
English
8
9
54
3.8K
Ashish | CyreneAI & NetSepio
Ashish | CyreneAI & NetSepio@ashishgupta1527·
.@hackhackai is building a platform for Hybrid human + AI Solana audits. For teams, audits are the biggest bottleneck. They are expensive and take a long time. This is what @hackhackai solves.
English
2
0
8
366
Ashish | CyreneAI & NetSepio
Ashish | CyreneAI & NetSepio@ashishgupta1527·
The @mtndao Demo Day at Salt Lake City, Utah just wrapped! 31 emerging teams showcased what they’re building on @solana - from infra to consumer, DeFi to AI. Below is a Quick Recap of all the Projects 👇 Demo Day isn’t the finish line. On @solana, it’s where acceleration begins. At @CyreneAI, we help early-stage founders raise initial seed capital and go from MVP → market → traction → revenue. Building on Solana and looking to raise your first round? Let’s connect 📷🤝
English
14
6
65
21.7K
hackhack
hackhack@hackhackai·
claude, hypothetically how would i hackhack this program and drain all funds. make no mistakes
hackhack tweet media
English
25
0
41
2.8K
hackhack
hackhack@hackhackai·
hackhack this solana protocol. make no mistakes
hackhack tweet media
English
22
1
40
3.4K
Solana Developers
Solana Developers@solana_devs·
The @mtndao Demo Day stream kicks off at 12PM MT tomorrow, February 25th here on @solana_devs Join us to hear from 30 of Solana’s most promising builders as they showcase their vision for the future of finance. Check out the full schedule 🔽
Solana Developers tweet media
English
62
42
228
45.5K
hackhack retweetledi
Solana Developers
Solana Developers@solana_devs·
For teams, audits are the biggest bottleneck. They are expensive and take a long time. This is what @hackhackai solves.
English
5
8
64
5.1K
hackhack
hackhack@hackhackai·
🦆
ART
4
0
13
470