Skip to content

Great Quotes Powerful Minds All what you need in one page

Great Quotes Powerful Minds All what you need in one page

  • Home
  • Terms and Conditions
  • Privacy policies
  • GPDR Privacy Notice
  • Contact Us
  1. Home
  2. /Business
  3. /Solana Wallet Hack: Here’s What We Know So Far

Solana Wallet Hack: Here’s What We Know So Far

Business / August 3, 2022 / Greatquotes / 0

In brief

  • Thousands of Solana software wallets have had tokens drained since last night in a widespread attack totaling nearly $4.5 million thus far.
  • The exploit is believed to be due to software in certain wallets, including Slope and Phantom. Hardware wallets are not affected.

Update, August 3, 4:50 pm ET: Solana developers say they have identified the root cause of the hack: compromised private keys “created, imported, or used in Slope mobile wallet applications.” Read the full details here.

Solana users far and wide last night were startled to find that their wallets were being drained of SOL, the USDC stablecoinand other Solana-based tokens in a widespread and ongoing hack. As of this writing, an estimated $4.46 million worth of coins and tokens have been nabbed so far.

According to blockchain explorer Solscan, the four identified attackers’ wallets have collectively attacked about 15,200 wallets, although there may be overlap between their targets. The official Solana Status account on Twitter pegged the tally at approximately 8,000 unique wallets as of earlier this morning.

As the attack apparently continues, the network’s core team and founder have started sharing theories on what’s happening. Per Solana Status, “engineers from across several ecosystems, in conjunction with audit and security firms, continue to investigate the root cause” of the attack.

Engineers from across several ecosystems, in conjunction with audit and security firms, continue to investigate the root cause of an incident that resulted in approximately 8,000 wallets being drained. 1/2

— Solana Status (@SolanaStatus) August 3, 2022

“This does not appear to be a bug with Solana core code,” it added, “but in software used by several software wallets popular among users of the network.”

That theory comports with evolving sentiment last night and overnight by Solana developers and security experts. Initially, some thought that the exploit had to do with lingering permissions that users’ may have previously granted to a smart contract, and many platforms—such as top NFT marketplace Magic Eden—urged Solana users to revoke any permissions.

However, that didn’t appear to help since transactions were being signed, thus suggesting a compromise of users’ private keys. Instead, as the Solana Status update suggests, the prevailing theory now is that code within software-based wallet apps is being exploited in some manner to enable access to holders’ assets.

Solana co-founder and Solana Labs CEO Anatoly Yakovenko tweeted overnight that it “sees like an iOS supply chain attack,” suggesting that the issue pertained to wallets used on Apple’s iPhone and iPad devices. However, based on additional evidence, he added in a subsequent tweet that Android users are being affected, as well.

Seems like an iOS supply chain attack. Multiple plausible wallets that only received sol and had no interactions beyond receiving have been affected. https://t.co/ne0g3ZmLH5

As well as key that was imported into iOS, and generated externally. https://t.co/hStAr1mU6Q

— SMS T◎ly, 🇺🇸 (@aeyakovenko) August 3, 2022

“All the confirmed stories so far have had the key imported or generated on mobile,” he wrote, noting that the majority of confirmed wallets were from Slope, with some from Phantom. Hardware wallets do not appear to be affected at all. Notable crypto investor Adam Cochran wrote this morning that he is “90% [sure] this is related to using Slope or importing into Slope.”

Asked by a user what Solana developers can do about this issue going forward, Yakovenko replied, “Fucking Apple and Google can give us secure signing and recovery in the device. F’ing hell.”

Slope’s Twitter account hasn’t tweeted since last night, when it wrote that the team was “actively working to sort out the issue.” Likewise, Phantom last tweeted yesterday evening with a similar message, but added that it did “not believe this is a Phantom-specific issue” at the time.

Blockchain security firm OtterSec has asked affected users to fill out a form with details of their wallet and activity. Yakovenko and other notable Solana developers have shared the same form in the hopes of amassing more data on the exploit.

lmao you can’t make this up – some madlad started DOSing the hacker which caused the RPC nodes to start failing

FYI – the chain is fine pic.twitter.com/AzbEvFLft4

— mert | Helius ☀ (@0xMert_) August 3, 2022

The Solana network was at times inaccessible or difficult to use last night due to partial outages with RPC nodes that facilitate network traffic. Allegedly, the slowdown was due to the efforts of a user who attempted to slow or stop the attack by overwhelming the Solana network with transactions in a DDOS-like frenzy.

Solana (SOL) initially saw a significant price drop in the wake of the last night’s initial attacks, with the price dropping about 8% in a two-hour span. However, it has been rebounded somewhat to a current price of just over $40 per coin, or about a 2% dip over the last 24 hours.

Stay on top of crypto news, get daily updates in your inbox.

Related

Greatquotes

NBA 2K23 Preview: Polish Is the Priority Italy police seize assets from architect linked to Russia

Related posts

Wide-body jet demand humming again as Boeing 787 rejoins the fray

Wide-body jet demand humming again as Boeing 787 rejoins the fray

Rivian lost .7 billion in three months.  Here’s why that may not be a problem

Rivian lost $1.7 billion in three months. Here’s why that may not be a problem

Folks React To Domino’s Pizza Closing Its Doors To The Last Store In Italy After Failing To Impress Locals

Folks React To Domino’s Pizza Closing Its Doors To The Last Store In Italy After Failing To Impress Locals

Big Protein Shake, Plant Milk and Coffee Recall: Alternatives and More

Big Protein Shake, Plant Milk and Coffee Recall: Alternatives and More

CEO Posts A Crying Selfie After Laying Off Employees, Receives A Major Backlash

CEO Posts A Crying Selfie After Laying Off Employees, Receives A Major Backlash

Ominous Solana technicals hint at SOL price crashing 35% by September

Ominous Solana technicals hint at SOL price crashing 35% by September

Latest posts

Europe’s heatwaves, droughts put focus on climate change risks |  News

Europe’s heatwaves, droughts put focus on climate change risks | News

Wide-body jet demand humming again as Boeing 787 rejoins the fray

Wide-body jet demand humming again as Boeing 787 rejoins the fray

All 3 Steelers QBs including rookie Kenny Pickett play well

All 3 Steelers QBs including rookie Kenny Pickett play well

Kevin Federline Needs to Keep Britney Spears’ Name Out of His Mouth and Get a Real Job

Kevin Federline Needs to Keep Britney Spears’ Name Out of His Mouth and Get a Real Job

Rivian lost .7 billion in three months.  Here’s why that may not be a problem

Rivian lost $1.7 billion in three months. Here’s why that may not be a problem

Steelers Vs Seahawks Winners And Losers

Steelers Vs Seahawks Winners And Losers

Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Europe’s heatwaves, droughts put focus on climate change risks | News
  • Wide-body jet demand humming again as Boeing 787 rejoins the fray
  • All 3 Steelers QBs including rookie Kenny Pickett play well
  • Kevin Federline Needs to Keep Britney Spears’ Name Out of His Mouth and Get a Real Job
  • Rivian lost $1.7 billion in three months. Here’s why that may not be a problem

Categories

  • World
  • Sports
  • Health
  • Technology
  • Business
  • Entertainment
  • Science

Copyright © 2022 Great Quotes Powerful Minds

Search