The Auditors Signed Off. The Money Left Anyway.
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Data from Blockaid, Global Ledger, and TRM Labs shows that in the first half of 2026, 74% of crypto losses (roughly $1.1B out of 212 verified onchain exploits) came from operational failures rather than smart contract bugs. Case studies include Drift Protocol ($285M via a weeks-long social engineering campaign against admin multisig holders, drained in under 12 minutes), KelpDAO ($292M via a compromised LayerZero developer poisoning RPC infrastructure), and Ostium ($23.75M via a price-submission authority abusing a pull-based oracle with no sanity checks). Both Drift and KelpDAO were linked to Lazarus Group's TraderTraitor cluster, which took ~$609M in the half-year. The piece argues that key-compromise losses almost never get recovered, unlike protocol-bug losses, and proposes five defenses: timelocks on privileged actions, eliminating single points of failure across keys/devices, treating off-chain inputs as hostile with sanity bands, rate-limiting and circuit-breaking outflows, and training team members against social engineering.
Table of contents
Season 2: PROTOCOL ZERO, Chapter 7 | The Human ExploitPreviously in PROTOCOL ZERO…1. The Twelve-Minute Protocol2. The $292 Million Lie Told to a Bridge3. The Price Is a PersonGet Tabrez Mukadam ’s stories in your inbox4. Why This Is Worse Than a Bug5. Auditor’s Fix / Defense ArchitectureThe Takeaway🔌 Let’s ConnectQuestions this post answers
How did the Drift Protocol $285 million exploit on Solana actually happen?
Attackers ran a weeks-long targeted social engineering campaign against specific Drift Protocol team members with privileged access, eventually gaining administrative multisig control. From there they fabricated collateral pricing data and drained approximately $285 million, the largest exploit in Solana's history, in under twelve minutes from the first malicious transaction. Teams hardening admin key security against social engineering follow incident breakdowns like this on daily.dev.
How did attackers drain $292 million from KelpDAO without breaking any cryptography?
Attackers socially engineered a LayerZero developer to gain access, then used it to poison RPC infrastructure feeding false bridge configuration data. A phantom burn on one chain released 116,500 rsETH on another, and the verifier worked correctly but was fed lies; the fake rsETH was then posted as collateral on Aave to borrow real ETH before withdrawal. Developers designing cross-chain bridge trust assumptions track incidents like this on daily.dev.
Why did the Ostium DEX oracle exploit succeed even though the signature check passed correctly?
Ostium used a pull-based oracle accepting a signed price at settlement with no independent cross-check on the submitted value. An attacker with price-submission authority opened BTC longs at $5,000 and closed them near $60,000, prices that never traded anywhere, extracting $23.75 million because the contract only verified signer authenticity, not price sanity. Anyone designing oracle input validation weighs tradeoffs like this by following DeFi security writeups on daily.dev.