The truth behind the Drift exploit
The team publicly claimed to have retained third-party cybersecurity firms to investigate the incident. To date, no official forensic report, confirmation of engagement, or technical evidence has been published.
A multisig migration and Security Council update were executed 48 hours prior to the exploit without public rationale. One signer key from the previous council was retained in the new deployment and subsequently initiated the initial attack payload transaction.