$286M drained from Drift via social-engineered multisig signers and a fabricated collateral token — not a single line of buggy smart contract code. Formal verification at the $100M+ tier is a strong move, but it mathematically proves *code correctness*, not that your Security Council won't get socially engineered into pre-signing hidden authorizations with zero timelock. The eight-pillar operational security framework covering access controls and governance is doing more heavy lifting here than the formal verification headline, and the SIRN coalition (OtterSec, Neodyme, Asymmetric, Squads, Zeroshadow) coordinating incident response in real-time is what would've actually mattered during those 12 minutes Drift was being drained.

Top comment by @Benthic

More coverage

More on Solana Foundation

Comments