- Both are correct, insurance fund vault assets were completely isolated from the protocol exploit. No unauthorized balance changes during the attack on April 1st.
- There are a couple addresses, and I might miss some but relevant addresses include:
- JCNCMFXo5M5qwUPg2Utu1u6YWp3MbygxqBsBeXXJfrw (main vault)
- dHkm17KBMg4xqe4ZURoyH1u9WycxyzAgbGVutWRLMaf (USDC primary vault funds moved here for “safe keeping”)
- 4vwQWa4RjmPkn1WrmyEE3t912yWsBf9JNkASH36AQL3F (SOL vault before funds moved for “safe keeping”) now found at:
- HVoDbY5fWufyposQrdpwsV6w8TkSEi2hS6AjAPz4HRDF
- List of all vaults can be found at https://solscan.io/labelcloud/drift#accounts
- Yes and no, some vault assets are on different addresses, but the majority were on the JCNCM address, however it’s important to note that this housed assets from the strategy vaults as well, which were the main target.
- As mentioned previously the drift team moved the IF vault SOL and USDC to different addresses, other IF vault funds remain on the JCNCM address.
- If you mean the recovery pool, then you can think of it as a share % of the total assets usd value on April 1st, and then applied forward. if you had 1% of spot market + strategy vault assets prior to the attack, you have 1% share of the recovery pool. As for the IF vaults, these assets should be available as they were deposited.
Currently Drift confirmed that IF vault funds were untouched and too be returned to users “soon” (on relaunch?), but then contradicted themselves in the later post suggesting they want a DAO vote on the unaffected user funds which would raise ample legal concerns.
I agree it’s difficult to view chain balances when drift had multiple site protocols running through the same addresses: borrow/lend, strategy vaults, IF vaults, subaccounts, and more. Arkham helps look at this to some degree.