frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Solana Drift Protocol drained of $285M via fake token and governance hijack

https://anonhaven.com/en/news/drift-protocol-hack-285-million-solana/
55•anonhaven•2h ago

Comments

edm0nd•1h ago
Their CEO should serve prison time for being so incompetent but hey c-levels almost never get punished which is sad.
ph4rsikal•1h ago
https://www.web3isgoinggreat.com/
Overpower0416•1h ago
What kind of DeFi protocol has super power private keys to alter the protocol just like that? And no timelock. Seriously? What a joke
KK7NIL•1h ago
Seems to be very standard now a days as projects seek to do things that can't be done fully on-chain.

You'd think they'd take a step back and ask "why is this even a token then?".

Overpower0416•1h ago
All changes should be voted upon no matter if onchain or offchain. After that there should be a timelock, so people that don't agree with the vote to pull their assets if they want to. The only power these private keys should have is to pause the market if there is a major bug or exploit.
lokar•1h ago
It's a token so they can make $
embedding-shape•1h ago
> The attacker used social engineering to induce Drift Security Council multisig signers into pre-signing transactions that appeared routine but carried hidden authorisations.

So much for the "Security Council". What an embarrassment to be in a team/org like that and fail your most basic duty which would be "look at what you sign".

lokar•1h ago
That was inevitable, and all designs like that will eventually yield the same outcome.

The people who should be embarrassed are the ones who thought having a group of humans routinely review (possibly complex) transactions for correctness, with no ability to undo/revert the outcome, was a good idea.

lokar•1h ago
Also, how could one reasonably disprove that the signers were not in on the scam?
bombcar•59m ago
That’s the best part, you can’t!
sebgan•14m ago
This is conveniently suspect, no? “Drift migrated its Security Council on March 27 to a new 2-of-5 threshold with zero timelock. That eliminated the delay that would have allowed detection before admin actions took effect.” This was after the perp started working on the heist earlier in the month.
simonw•1h ago
So this is the end of the Drift project, right?

Back at the top of the crypto hype cycle I wouldn't be surprised to see a project survive even a situation like this one, but now that the hype has died down is it still possible to come back from a loss of this magnitude?

andxor•1h ago
Hyperliquid.
estetlinus•1h ago
> The funds were used to deploy CarbonVote Token (CVT), a completely fictitious asset

Crypto calling out other cryptos, made me giggle

rvnx•1h ago
+ "ZachXBT publicly criticised Circle for not freezing the stolen USDC during the bridge"

calling for this, when the whole concept is to avoid government control

haakon•50m ago
Backed stablecoins aren't some anarchistic anti-government thing; they are highly regulated and will lose access to their banking if they don't follow the rules – rules which require them to freeze coins in cases of crime.

If you want to show a middle finger to government there are cryptocurrencies for that, but USD stablecoins with centralized backing is not it.

rvba•1h ago
It feels like main purpose of those various coins are scams. Either classic pump and dump, or advanced ones based on complex interactions.
yieldcrv•1h ago
this is a beautiful attack, the way that multisig signers were compromised with innocuous signatures in advance, without really compromising private keys

from the pre-funding to a virgin address, to the bundler, to the exit strategy to decentralized assets

to the protocols exposed but functioning perfectly under the stress test - props to Jupiter! - and the optional insurance protocols functioning decently, all while people point fingers at Circle for their bridge working perfectly, it's not even clear what people want them to do specifically! All of these aspects of web3 are working great, and it's easy for a cynic that only sees these headlines to miss that

inspirational, great place to build

pawelduda•1h ago
Trusting any of these crypto protocols is hard with any serious money. If anyone wants to target you, they'll go great lengths to trick you into making a mistake. Even if you do everything right, the people behind the service can step into a mine for you. Even easier if you add AI to the pipeline where people will tend to offload the vulnerable parts of development/ops to a LLM
verdverm•1h ago
Is public-permissionless just a bad fundamental?
vessenes•1h ago
The multisig UI/UX is a real and long term difficulty for any governance council. "Please sign this opaque transaction with binary data, it represents our agreement. I promise." For a while maybe ten years ago I worked with MakerDAO on this problem - at the time the idea was a separate auditor for proposed transactions.

This general attack pattern is: get a lender with good collateral to call your bad collateral good, then swap collaterals, and it's a known and bad attack vector; the ongoing tension between innovation / speed and caution continues.

There's probably a flash-loan multiplier angle here for an even worse attack; I'm imagining chaining a liquidity change in the trusted price oracle for the CVT token in the middle of the swapping. Anyway, upshot - don't loan against North Korean attack tokens. Put it on the list.

maipen•1h ago
It took a long time until we got real digital money, Bitcoin.

But all these new protocols want to do stuff at the expense of trustlesssness.

Night_Thastus•30m ago
Bitcoin isn't 'real digital money'. It's a speculative asset for gambling with. That's all it is, and all it ever was.
youniverse•40m ago
What a nice retirement fund!
nradov•37m ago
It's always entertaining to see worthless idiots lose money on an obvious scam like cryptocurrency. Ha ha. Although in this case it seems that North Koreans might have ended up with actual valuable fiat currency, which is unfortunate.
fnoef•7m ago
Remind me again how cryptocurrency is the future of money, and is definitely not used, primarily, for scams

iNaturalist

https://www.inaturalist.org/
174•bookofjoe•2h ago•50 comments

Show HN: I built a frontpage for personal blogs

https://text.blogosphere.app/
515•ramkarthikk•7h ago•145 comments

We replaced RAG with a virtual filesystem for our AI documentation assistant

https://www.mintlify.com/blog/how-we-built-a-virtual-filesystem-for-our-assistant
107•denssumesh•1d ago•55 comments

How to Make a Sliding, Self-Locking, and Predator-Proof Chicken Coop Door (2020)

https://www.backyardchickens.com/articles/how-to-make-a-sliding-self-locking-and-predator-proof-c...
16•uticus•51m ago•2 comments

Go on Embedded Systems and WebAssembly

https://tinygo.org/
53•uticus•2h ago•7 comments

Samsung Magician disk utility takes 18 steps and two reboots to uninstall

https://chalmovsky.com/2026/03/29/samsung-magician.html
318•chalmovsky•4d ago•163 comments

Age Verification on Systemd and Flatpak

https://cybrkyd.com/post/age-verification-on-systemd-and-flatpak/
20•londonanon•28m ago•8 comments

Show HN: TurboQuant for vector search – 2-4 bit compression

https://github.com/RyanCodrai/py-turboquant
61•justsomeguy1996•5d ago•5 comments

Async Python Is Secretly Deterministic

https://www.dbos.dev/blog/async-python-is-secretly-deterministic
14•KraftyOne•50m ago•8 comments

F-15E jet shot down over Iran

https://www.theguardian.com/world/2026/apr/03/us-fighter-jet-confirmed-shot-down-over-iran
130•tjwds•3h ago•300 comments

Build your own Dial-up ISP with a Raspberry Pi

https://www.jeffgeerling.com/blog/2026/build-your-own-dial-up-isp-with-a-raspberry-pi/
50•arjunbajaj•4h ago•14 comments

April 2026 TLDR Setup for Ollama and Gemma 4 26B on a Mac mini

https://gist.github.com/greenstevester/fc49b4e60a4fef9effc79066c1033ae5
248•greenstevester•10h ago•101 comments

A Recipe for Steganogravy

https://theo.lol/python/ai/steganography/seo/recipes/2026/03/27/a-recipe-for-steganogravy.html
109•tbrockman•5d ago•27 comments

SSH certificates: the better SSH experience

https://jpmens.net/2026/04/03/ssh-certificates-the-better-ssh-experience/
154•jandeboevrie•9h ago•66 comments

You can now run a full Linux operating system inside a 6mb PDF

https://twitter.com/oliviscusAI/status/2038563166431346865
28•matthewsinclair•3d ago•3 comments

Show HN: An evidence-rated encyclopedia of peptides

https://www.whatthepeptide.org/
15•uelbably•1h ago•2 comments

Update on the eBay Scam

https://kevquirk.com/update-on-the-ebay-scam
5•speckx•1h ago•4 comments

Big-Endian Testing with QEMU

https://www.hanshq.net/big-endian-qemu.html
71•jandeboevrie•6h ago•63 comments

Firm boosts H.264 streaming license fees from $100k up to staggering $4.5M

https://www.tomshardware.com/service-providers/streaming/h264-streaming-license-fees-jump-from-10...
35•MaximilianEmel•1h ago•28 comments

Show HN: Apfel – The free AI already on your Mac

https://apfel.franzai.com
578•franze•10h ago•132 comments

If you're running OpenClaw, you probably got hacked in the last week

https://old.reddit.com/r/sysadmin/comments/1sbdw29/if_youre_running_openclaw_you_probably_got_hac...
185•kykeonaut•3h ago•123 comments

What Category Theory Teaches Us About DataFrames

https://mchav.github.io/what-category-theory-teaches-us-about-dataframes/
154•mchav•5d ago•48 comments

ESP32-S31: Dual-Core RISC-V SoC with Wi-Fi 6, Bluetooth 5.4, and Advanced HMI

https://www.espressif.com/en/news/ESP32_S31_Release
170•topspin•5d ago•101 comments

TDF ejects its core developers

https://meeksfamily.uk/~michael/blog/2026-04-02-tdf-ejects-core-devs.html
134•janvdberg•7h ago•88 comments

The Technocracy Movement of the 1930s

https://donotresearch.substack.com/p/welcome-to-the-technocracy
54•lazydogbrownfox•17h ago•41 comments

Category Theory Illustrated – Types

https://abuseofnotation.github.io/category-theory-illustrated/06_type/
66•boris_m•9h ago•1 comments

Solana Drift Protocol drained of $285M via fake token and governance hijack

https://anonhaven.com/en/news/drift-protocol-hack-285-million-solana/
55•anonhaven•2h ago•25 comments

NHS staff refusing to use FDP over Palantir ethical concerns

https://www.freevacy.com/news/financial-times/nhs-staff-refusing-to-use-fdp-over-palantir-ethical...
278•chrisjj•10h ago•126 comments

What we learned building 100 API integrations with OpenCode

https://nango.dev/blog/learned-building-200-api-integrations-with-opencode/
75•rguldener•3d ago•18 comments

Google releases Gemma 4 open models

https://deepmind.google/models/gemma/gemma-4/
1695•jeffmcjunkin•1d ago•449 comments