Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.
← back to incident ledger

access control missingDemo

Aug 22, 2025 · $1.4M · protocol

Narrative

On 2025-08-22, Drift Protocol suffered a access control missing incident resulting in approximately $1,401,640 in losses. The exploit targeted the protocol layer. Attribution: unattributed_criminal. This is a demonstration entry — not a real incident.

Classification

Root cause
access_control_missing
Secondary causes
Attack layer
protocol
Strategy
tech_vuln
Actor role
target
Attribution
unattributed_criminal
Attacker address
0x55e86c029b2a061e142920b96f38c02dd8d157cc
Flash loan
no
Audited at time
no
Bounty at time
no

AADAPT mappings

DEMO:AADAPT.TA0004DEMO:AADAPT.TA0006DEMO:AADAPT.T1078

Evidence

Disclosure date
Aug 24, 2025
Funds recovered
Audit firms at time
Post-mortem URLs (synthetic)
  • https://medium.com/drift-protocol/post-mortem-drift-protocol-2025-08-22
  • https://rekt.news/drift-protocol-rekt
tx hashes (2)
  • 0xe91e01c5b2b040adc1558d17571ac0bb83504f4c59ca97dd14a41f0e7ac6913e
  • 0x64af911bab1e0a7abc2aa604dca1059aff2bd890e644c5a26186843edc3a5966