From the Drift Hack to an Open Source Security Tool: A Complete Introduction to crypto-project-security-skill

From the Drift Hack to an Open Source Security Tool: A Complete Introduction to crypto-project-security-skill

中文 EN

After Drift Protocol was hacked for $285 million, I spent a week doing one thing: turning every lesson learned from the post-mortem into an automated tool that can catch problems before they happen.

This tool is a Claude Code Skill -- a security audit framework that can be directly invoked by an AI coding assistant. It's called crypto-project-security-skill, and it's now open source on GitHub.

This article provides a complete introduction to the tool's design philosophy, how it works, and its validation results across 56 protocols.


Why This Tool Is Needed

The most shocking aspect of the Drift incident wasn't the amount -- it was the attack vector: no smart contract vulnerability was exploited. The attacker obtained pre-signed signatures from multisig members through social engineering, then leveraged a zero-timelock governance architecture to drain the treasury in 12 minutes.

Traditional DeFi security audits focus almost entirely on the code level -- finding reentrancy bugs, overflows, and logic errors. But the Drift case proved that governance architecture, admin key permissions, and timelock configurations -- these "non-code" security layers -- are the real fatal weaknesses.

Existing security tools also have blind spots:

  • Smart contract audit firms (Trail of Bits, OpenZeppelin) focus on code review
  • DeFiLlama provides TVL data but doesn't do security assessments
  • GoPlus does token-level honeypot detection but doesn't cover governance analysis
  • rekt.news records incidents after the fact, not before

No single tool integrates all these dimensions to provide a comprehensive assessment from governance to oracles to economic mechanisms. That's the problem crypto-project-security-skill aims to solve.


Design Philosophy: Governance First

The most critical design decision in this tool is doubling the governance weight.

In traditional security scoring, smart contract vulnerabilities typically carry the highest weight. But based on attack data from 2024-2026, fund losses caused by governance and admin key issues have already surpassed those from pure code vulnerabilities. Drift (285M),RadiantCapital(285M), Radiant Capital (50M), Beanstalk ($182M) -- none of these were code problems.

Therefore, in the final risk rating:

  • Governance and admin key scoring weight is 2x that of other categories
  • If the governance category is rated CRITICAL, the overall rating is CRITICAL
  • If any two categories are rated HIGH, the overall rating is HIGH

This weighting logic directly reflects the real-world distribution of attacks.


Ten-Step Audit Workflow

The entire audit is divided into ten steps, from quick screening to a complete report:

Step 0: Quick Triage

The first step isn't deep analysis but rather a quick determination of whether the protocol is worth investigating further. The tool will:

  • Pull TVL data from the DeFiLlama API
  • Scan token security via the GoPlus Security API (honeypot detection, holder concentration, trading restrictions)
  • Calculate a 0-100 mechanical triage score and a 0-100 data confidence score

The mechanical triage score is based on red flag deductions: no audit deducts 20 points, TVL below $10M deducts 15 points, token flagged as honeypot goes straight to zero. The data confidence score measures how much information we can verify -- if most data is "UNVERIFIED," the confidence score will be low, which itself is a risk signal.

Step 1: Information Gathering

Broad collection of the protocol's public information:

  • Architecture documents, whitepapers
  • Historical security incidents (specifically querying rekt.news)
  • Audit report history
  • Governance configuration (multisig thresholds, timelocks, upgrade mechanisms)
  • Bug bounty programs
  • Selection of 2-3 similar protocols with comparable TVL as a comparison group

Steps 2-4: Three Pillar Deep Analysis

This is the core of the audit, evaluating three dimensions independently:

Governance and Admin Keys (2x Weight)

  • Multisig configuration: what's the threshold (M-of-N)? Who are the signers?
  • Timelock duration: does one exist? How long? Can it be bypassed?
  • Upgrade mechanism: are contracts upgradeable? Who has upgrade authority?
  • Token concentration: what percentage do the top 10 holders own? Is there whale risk?

Oracles and Price Feeds

  • Which oracle providers are used? (Chainlink, Pyth, custom-built)
  • Is there a fallback mechanism?
  • How resistant is it to price manipulation?

Economic Mechanisms

  • Is the liquidation design sound?
  • Is the insurance fund size adequate relative to TVL?
  • What is the bad debt handling mechanism?

Steps 5-7: Supplementary Analysis

  • Smart Contract Security: audit history, bug bounty size, battle-tested duration
  • Cross-Chain and Bridge Risk: multi-chain admin keys, bridge dependencies, cross-chain message security
  • Operational Security: team track record, incident response capability, external dependencies

Step 8: On-Chain Verification

This is the most critical differentiating step. The tool doesn't just look at what documentation says -- it actually verifies on-chain:

# Gnosis Safe multisig verification
curl -s "https://safe-transaction-mainnet.safe.global/api/v1/safes/{address}/"

# Etherscan contract verification
curl -s "https://api.etherscan.io/api?module=contract&action=getabi&address={address}"

# Solana program upgrade authority
solana program show {program_id}

# Squads multisig detection (Solana)
curl -s "https://api.solana.fm/v0/accounts/{address}"

If a protocol claims to use a 3/5 multisig, the tool will directly query the Safe API to verify. If it claims a contract is non-upgradeable, it will check on-chain to confirm. Documentation can deceive; on-chain data cannot.

Steps 9-10: Report Generation

The final report includes:

  • Quantitative metrics (insurance/TVL ratio, audit coverage rate, governance decentralization score)
  • Peer protocol comparison table
  • Cross-reference against 8 known attack patterns
  • Information gap list (what couldn't be verified)
  • Risk rating (LOW / MEDIUM / HIGH / CRITICAL)

Eight Attack Pattern Checklists

The tool includes 8 attack patterns distilled from major historical attack incidents:

PatternRepresentative IncidentCore Characteristics
Drift TypeDrift $285MGovernance hijack + fake collateral + pre-signed transactions
Euler/Mango TypeMango $110MOracle manipulation + low-liquidity tokens
Ronin/Harmony TypeRonin $625MValidator/multisig key compromise
Beanstalk TypeBeanstalk $182MFlash loan governance attack
Cream/bZx TypeCream $130MReentrancy attack + lending protocols
Curve TypeCurve $70MCompiler vulnerability
UST/LUNA TypeLUNA $40BAlgorithmic stablecoin depeg
Bybit TypeBybit $1.4BNation-state APT + social engineering

If a protocol matches more than 3 characteristics in any single pattern, a warning is triggered.


Validation Results: 56 Protocols

The tool has completed validation on 56 of the top 100 TVL protocols on DeFiLlama, with the following distribution:

  • 7 LOW: Aave, Lido, Morpho, Sky/MakerDAO, Uniswap, SparkLend, Compound
  • 35 MEDIUM: EigenLayer, Ethena, Hyperliquid, Ondo, etc.
  • 11 HIGH: JustLend, SushiSwap, Radiant Capital, etc.
  • 3 CRITICAL: Drift Protocol (correctly identified all 3 attack vectors before the incident), Notional Finance (shut down), Lybra Finance (abandoned)

The most important validation: the tool was able to identify all three attack vectors before Drift was attacked. This is not hindsight -- if someone had run this audit on Drift in March, all the red flags would have been flagged.


Data Sources and Technical Architecture

The tool integrates multiple free APIs with no paid subscriptions required:

Data SourcePurposeCost
DeFiLlamaTVL, audit counts, protocol metadataFree
GoPlus SecurityHoneypot detection, holder permissions, trading restrictionsFree
Safe Transaction ServiceGnosis Safe multisig verificationFree
EtherscanContract verification, proxy detectionFree (API key required)
Solana RPC + SolanaFMProgram authority, account type detectionFree
RugCheck / BirdeyeSolana token fallback (GoPlus doesn't support Solana)Free

The entire tool consists of one SKILL.md file plus two shell scripts:

  • SKILL.md: approximately 500 lines of Claude Code skill definition, containing the complete audit workflow, API endpoints, scoring formulas, and report templates
  • scripts/goplus-check.sh: wrapper script for the GoPlus API
  • scripts/onchain-check.sh: wrapper script for on-chain verification (Safe, Etherscan, Solana RPC)

Installation and Usage

Three installation methods:

# skills.sh (Vercel)
npx skills add truenorth-lj/crypto-project-security-skill

# ClawHub (OpenClaw)
clawhub install truenorth-lj/crypto-project-security-skill

# Manual installation
# Copy SKILL.md to .claude/skills/defi-security-audit/SKILL.md

Once installed, trigger it in Claude Code using natural language:

  • "audit defi Aave"
  • "analyze protocol Hyperliquid"
  • "check security of Drift"
  • "is Compound safe?"

The tool will automatically execute the complete ten-step audit workflow and produce a structured security report.


Limitations and Disclaimer

This tool is not a silver bullet. It has clear limitations:

  1. No code auditing: The tool does not read or analyze smart contract source code; it focuses on architecture-level security assessment
  2. Relies on public information: If a protocol hasn't published its multisig addresses or governance configuration, the tool can only flag it as "UNVERIFIED"
  3. Snapshot, not monitoring: Each audit is a point-in-time snapshot, not continuous monitoring. A protocol may change its configuration after an audit
  4. Not investment advice: Risk ratings are technical assessments, not investment advice

From Drift to Tool: Motivation

The motivation for building this tool is straightforward: the Drift incident exposed a systemic blind spot -- the DeFi security community is overly focused on code while neglecting governance.

If, when Drift migrated to a zero-timelock 2/5 multisig, a tool had automatically flagged "CRITICAL: zero timelock + low-threshold multisig = governance hijack risk," perhaps the outcome would have been different.

This tool cannot prevent every attack, but it ensures that before committing funds, you've at least asked the right questions. In the world of DeFi, asking the right questions is sometimes the best defense.


Open source repository: truenorth-lj/crypto-project-security-skill License: MIT License


References