How a Solana feature designed for convenience let attackers drain more than $270 million from Drift

The exploit did not involve a bug in Drift’s code. It used “durable nonces,” a legitimate Solana transaction feature, to pre-sign administrative transfers weeks before executing them, bypassing the protocol’s multisig security in minutes.