What happened
Signers were socially engineered into pre-signing hidden authorizations; zero-timelock council migration.
Transaction-level mechanics
Public post-incident disclosures do not include full transaction calldata or execution traces for this incident.
TODO: Add exact Safe transaction hash, decoded actions, and the on-chain state changes once verified primary sources are available. For now, the attack vector summary above is derived from public reporting.
What independent decoding / hash verification / config scanning would have caught
Solana / Drift is out of scope today. The underlying issue was socially engineered pre-signing, which no on-chain tool can prevent once signers approve.
Verdict
Out of scope