Colin Charles pfp
Colin Charles

@bytebot

Drift protocol update 6 months in the making, and maybe the most interesting bits are: 1. compromise via cloned code repo under the guise of deploying a frontend for their vault 2. TestFlight application, for wallet product (this is probably not a vector - app sandboxing) 3. "For the repository-based vector, one possibility is a known VSCode and Cursor vulnerability that the security community was actively flagging throughout December 2025 through February 2026. Simply opening a file, folder, or repository in the editor was sufficient to silently execute arbitrary code, with no prompt or indication to the user, clicks, permissions dialog or warning of any kind." Yeah, beware of what repos are trusted... https://x.com/DriftProtocol/status/2040611161121370409
0 reply
0 recast
7 reactions