From the Drift Hack to an Open Source Security Tool: A Complete Introduction to crypto-project-security-skill
After Drift Protocol was hacked for $285 million, I spent a week doing one thing: turning every lesson learned from the post-mortem into an automated tool that can catch problems before they happen.
This tool is a Claude Code Skill -- a security audit framework that can be directly invoked by an AI coding assistant. It's called crypto-project-security-skill, and it's now open source on GitHub.
This article provides a complete introduction to the tool's design philosophy, how it works, and its validation results across 56 protocols.
Why This Tool Is Needed
The most shocking aspect of the Drift incident wasn't the amount -- it was the attack vector: no smart contract vulnerability was exploited. The attacker obtained pre-signed signatures from multisig members through social engineering, then leveraged a zero-timelock governance architecture to drain the treasury in 12 minutes.
Traditional DeFi security audits focus almost entirely on the code level -- finding reentrancy bugs, overflows, and logic errors. But the Drift case proved that governance architecture, admin key permissions, and timelock configurations -- these "non-code" security layers -- are the real fatal weaknesses.
Existing security tools also have blind spots:
- Smart contract audit firms (Trail of Bits, OpenZeppelin) focus on code review
- DeFiLlama provides TVL data but doesn't do security assessments
- GoPlus does token-level honeypot detection but doesn't cover governance analysis
- rekt.news records incidents after the fact, not before
No single tool integrates all these dimensions to provide a comprehensive assessment from governance to oracles to economic mechanisms. That's the problem crypto-project-security-skill aims to solve.
Design Philosophy: Governance First
The most critical design decision in this tool is doubling the governance weight.
In traditional security scoring, smart contract vulnerabilities typically carry the highest weight. But based on attack data from 2024-2026, fund losses caused by governance and admin key issues have already surpassed those from pure code vulnerabilities. Drift (50M), Beanstalk ($182M) -- none of these were code problems.
Therefore, in the final risk rating:
- Governance and admin key scoring weight is 2x that of other categories
- If the governance category is rated CRITICAL, the overall rating is CRITICAL
- If any two categories are rated HIGH, the overall rating is HIGH
This weighting logic directly reflects the real-world distribution of attacks.
Ten-Step Audit Workflow
The entire audit is divided into ten steps, from quick screening to a complete report:
Step 0: Quick Triage
The first step isn't deep analysis but rather a quick determination of whether the protocol is worth investigating further. The tool will:
- Pull TVL data from the DeFiLlama API
- Scan token security via the GoPlus Security API (honeypot detection, holder concentration, trading restrictions)
- Calculate a 0-100 mechanical triage score and a 0-100 data confidence score
The mechanical triage score is based on red flag deductions: no audit deducts 20 points, TVL below $10M deducts 15 points, token flagged as honeypot goes straight to zero. The data confidence score measures how much information we can verify -- if most data is "UNVERIFIED," the confidence score will be low, which itself is a risk signal.
Step 1: Information Gathering
Broad collection of the protocol's public information:
- Architecture documents, whitepapers
- Historical security incidents (specifically querying rekt.news)
- Audit report history
- Governance configuration (multisig thresholds, timelocks, upgrade mechanisms)
- Bug bounty programs
- Selection of 2-3 similar protocols with comparable TVL as a comparison group
Steps 2-4: Three Pillar Deep Analysis
This is the core of the audit, evaluating three dimensions independently:
Governance and Admin Keys (2x Weight)
- Multisig configuration: what's the threshold (M-of-N)? Who are the signers?
- Timelock duration: does one exist? How long? Can it be bypassed?
- Upgrade mechanism: are contracts upgradeable? Who has upgrade authority?
- Token concentration: what percentage do the top 10 holders own? Is there whale risk?
Oracles and Price Feeds
- Which oracle providers are used? (Chainlink, Pyth, custom-built)
- Is there a fallback mechanism?
- How resistant is it to price manipulation?
Economic Mechanisms
- Is the liquidation design sound?
- Is the insurance fund size adequate relative to TVL?
- What is the bad debt handling mechanism?
Steps 5-7: Supplementary Analysis
- Smart Contract Security: audit history, bug bounty size, battle-tested duration
- Cross-Chain and Bridge Risk: multi-chain admin keys, bridge dependencies, cross-chain message security
- Operational Security: team track record, incident response capability, external dependencies
Step 8: On-Chain Verification
This is the most critical differentiating step. The tool doesn't just look at what documentation says -- it actually verifies on-chain:
# Gnosis Safe multisig verification
curl -s "https://safe-transaction-mainnet.safe.global/api/v1/safes/{address}/"
# Etherscan contract verification
curl -s "https://api.etherscan.io/api?module=contract&action=getabi&address={address}"
# Solana program upgrade authority
solana program show {program_id}
# Squads multisig detection (Solana)
curl -s "https://api.solana.fm/v0/accounts/{address}"
If a protocol claims to use a 3/5 multisig, the tool will directly query the Safe API to verify. If it claims a contract is non-upgradeable, it will check on-chain to confirm. Documentation can deceive; on-chain data cannot.
Steps 9-10: Report Generation
The final report includes:
- Quantitative metrics (insurance/TVL ratio, audit coverage rate, governance decentralization score)
- Peer protocol comparison table
- Cross-reference against 8 known attack patterns
- Information gap list (what couldn't be verified)
- Risk rating (LOW / MEDIUM / HIGH / CRITICAL)
Eight Attack Pattern Checklists
The tool includes 8 attack patterns distilled from major historical attack incidents:
| Pattern | Representative Incident | Core Characteristics |
|---|---|---|
| Drift Type | Drift $285M | Governance hijack + fake collateral + pre-signed transactions |
| Euler/Mango Type | Mango $110M | Oracle manipulation + low-liquidity tokens |
| Ronin/Harmony Type | Ronin $625M | Validator/multisig key compromise |
| Beanstalk Type | Beanstalk $182M | Flash loan governance attack |
| Cream/bZx Type | Cream $130M | Reentrancy attack + lending protocols |
| Curve Type | Curve $70M | Compiler vulnerability |
| UST/LUNA Type | LUNA $40B | Algorithmic stablecoin depeg |
| Bybit Type | Bybit $1.4B | Nation-state APT + social engineering |
If a protocol matches more than 3 characteristics in any single pattern, a warning is triggered.
Validation Results: 56 Protocols
The tool has completed validation on 56 of the top 100 TVL protocols on DeFiLlama, with the following distribution:
- 7 LOW: Aave, Lido, Morpho, Sky/MakerDAO, Uniswap, SparkLend, Compound
- 35 MEDIUM: EigenLayer, Ethena, Hyperliquid, Ondo, etc.
- 11 HIGH: JustLend, SushiSwap, Radiant Capital, etc.
- 3 CRITICAL: Drift Protocol (correctly identified all 3 attack vectors before the incident), Notional Finance (shut down), Lybra Finance (abandoned)
The most important validation: the tool was able to identify all three attack vectors before Drift was attacked. This is not hindsight -- if someone had run this audit on Drift in March, all the red flags would have been flagged.
Data Sources and Technical Architecture
The tool integrates multiple free APIs with no paid subscriptions required:
| Data Source | Purpose | Cost |
|---|---|---|
| DeFiLlama | TVL, audit counts, protocol metadata | Free |
| GoPlus Security | Honeypot detection, holder permissions, trading restrictions | Free |
| Safe Transaction Service | Gnosis Safe multisig verification | Free |
| Etherscan | Contract verification, proxy detection | Free (API key required) |
| Solana RPC + SolanaFM | Program authority, account type detection | Free |
| RugCheck / Birdeye | Solana token fallback (GoPlus doesn't support Solana) | Free |
The entire tool consists of one SKILL.md file plus two shell scripts:
SKILL.md: approximately 500 lines of Claude Code skill definition, containing the complete audit workflow, API endpoints, scoring formulas, and report templatesscripts/goplus-check.sh: wrapper script for the GoPlus APIscripts/onchain-check.sh: wrapper script for on-chain verification (Safe, Etherscan, Solana RPC)
Installation and Usage
Three installation methods:
# skills.sh (Vercel)
npx skills add truenorth-lj/crypto-project-security-skill
# ClawHub (OpenClaw)
clawhub install truenorth-lj/crypto-project-security-skill
# Manual installation
# Copy SKILL.md to .claude/skills/defi-security-audit/SKILL.md
Once installed, trigger it in Claude Code using natural language:
- "audit defi Aave"
- "analyze protocol Hyperliquid"
- "check security of Drift"
- "is Compound safe?"
The tool will automatically execute the complete ten-step audit workflow and produce a structured security report.
Limitations and Disclaimer
This tool is not a silver bullet. It has clear limitations:
- No code auditing: The tool does not read or analyze smart contract source code; it focuses on architecture-level security assessment
- Relies on public information: If a protocol hasn't published its multisig addresses or governance configuration, the tool can only flag it as "UNVERIFIED"
- Snapshot, not monitoring: Each audit is a point-in-time snapshot, not continuous monitoring. A protocol may change its configuration after an audit
- Not investment advice: Risk ratings are technical assessments, not investment advice
From Drift to Tool: Motivation
The motivation for building this tool is straightforward: the Drift incident exposed a systemic blind spot -- the DeFi security community is overly focused on code while neglecting governance.
If, when Drift migrated to a zero-timelock 2/5 multisig, a tool had automatically flagged "CRITICAL: zero timelock + low-threshold multisig = governance hijack risk," perhaps the outcome would have been different.
This tool cannot prevent every attack, but it ensures that before committing funds, you've at least asked the right questions. In the world of DeFi, asking the right questions is sometimes the best defense.
Open source repository: truenorth-lj/crypto-project-security-skill License: MIT License
References
- crypto-project-security-skill — Open source Claude Code Skill for DeFi security auditing
- Drift Protocol $285M Exploit (Yahoo Finance) — April 2026 governance hijack via social engineering and pre-signed transactions
- $285M Drift Hack Traced to DPRK Social Engineering (The Hacker News) — Six-month infiltration by North Korean state-linked group
- Radiant Capital $50M Hack (CoinDesk) — October 2024 multisig key compromise via device-level malware
- Radiant Capital - Rekt II (rekt.news) — Post-mortem of the Radiant Capital exploit
- Beanstalk Farms $182M Governance Exploit (CoinTelegraph) — April 2022 flash loan governance takeover
- Mango Markets $110M Oracle Manipulation (Blockworks) — October 2022 price manipulation exploit on Solana
- Ronin Network $625M Exploit (rekt.news) — March 2022 validator key compromise on the Axie Infinity bridge
- Cream Finance $130M Flash Loan Exploit (rekt.news) — October 2021 reentrancy and price manipulation attack
- Curve Finance $70M Vyper Compiler Exploit (CoinTelegraph) — July 2023 reentrancy bug in Vyper compiler versions 0.2.15-0.3.0
- UST/LUNA Collapse (Wikipedia) — May 2022 algorithmic stablecoin depeg causing $40B+ in losses
- Bybit $1.4B Hack (TechCrunch) — February 2025 Safe multisig exploit attributed to North Korea's Lazarus Group
- DeFiLlama — Open DeFi analytics platform for TVL, protocol metadata, and audit data
- GoPlus Security API — Token security detection and honeypot analysis API
- Safe Transaction Service — Gnosis Safe multisig wallet infrastructure and verification API
- Etherscan — Ethereum blockchain explorer for contract verification and proxy detection
- SolanaFM — Solana blockchain explorer for account and program analysis
- RugCheck — Solana token risk assessment tool
- Birdeye — Solana DeFi aggregator and token analytics
- Chainlink — Decentralized oracle network for price feeds
- Pyth Network — High-fidelity oracle network for DeFi applications
- rekt.news — DeFi exploit database and post-mortem analysis
- Trail of Bits — Smart contract security audit firm
- OpenZeppelin — Smart contract security audit firm and Solidity library
- Claude Code — Anthropic's AI coding assistant that supports skill-based workflows
- skills.sh (Vercel) — Open agent skills marketplace for Claude Code and other AI agents
- ClawHub (OpenClaw) — Community skill directory for Claude Code


