Clues but No Clarity in Mysterious Solana Wallet Hack

The Solana blockchain itself was not compromised, lead developers say, but some 8,000 wallets have lost cryptoassets

article-image

Blockworks Exclusive art by axel rangel

share

key takeaways

  • Founders tweeted there is no issue with the network itself
  • Investors may be advised to move their tokens to cold storage or exchanges

Thousands of Solana users have fallen victim to a mysterious exploit that began draining cryptoassets about 18 hours ago. So far over $5.2 million in assets has been stolen, according to estimates from data firm Elliptic, from nearly 8,000 wallets, as tracked by Dune Analytics. 

In addition to solana (SOL), a handful of Solana NFTs and over 300 Solana-based tokens were pilfered as well.

The root cause is still unclear, but signs point to a common thread among the affected members of the Solana community — they all interacted with the Slope mobile wallet.

Rather than a flaw in the Solana blockchain itself, the exploit likely stems from a bug in hot wallet software, according to Anatoly Yakovenko, Solana Labs co-founder.

Loading Tweet..

Solana Status, the blockchain’s hub for data and system performance, initially pointed the finger at software used by several popular wallets.

Loading Tweet..

Other Twitter users such as @HelpedHope have added to speculation that hot wallets — crypto storage solutions connected to the internet — on various operating systems from both mobile and desktop to iOS and Android were affected, while cold wallets were not.

However, private keys initially generated by another wallet, but then imported into Slope, may have subsequently been leaked, leading to the difficulty pinpointing a chain of events.

In a statement, the Slope team said they are “actively conducting internal investigations and audits, working with top external security and audit groups.”

While acknowledging uncertainties remain as to the cause, they advised all Slope users to “create a new and unique seed phrase wallet, and transfer all assets to this new wallet.”

This hack, while comparatively smaller than others, is significant because the perpetrator was not thought to be a lone actor, and the attack targeted thousands of individual wallets rather than a central source of funds such as an exchange or inter-blockchain bridge.  

Initially promoted as Ethereum’s main competitor, and currently the second-largest blockchain for NFTs after Ethereum, the Solana blokchain has had its share of issues.

Since the beginning of the year, the network has suffered five outages due to consensus failures and has gone offline for multiple hours on end. The latest occurred in June and took 4½ hours to rectify. 

The price of the SOL token has fallen nearly 4% in the past 24 hours, at the time of publication, according to data compiled by Blockworks.

This story was updated on August 3, 2022, at 5:02 pm ET with a statement from the Slope team.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the On the Margin newsletter.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Salt Lake City, UT

MON - TUES, OCT. 7 - 8, 2024

Blockworks and Bankless in collaboration with buidlbox are excited to announce the second installment of the Permissionless Hackathon – taking place October 7-8 in Salt Lake City, Utah. We’ve partnered with buidlbox to bring together the brightest minds in crypto for […]

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Permissionless is a conference for founders, application developers, and users. Come meet the next generation of people building and using crypto.

recent research

Research Report Templates (1).png

Research

Solana Mobile is a highly ambitious foray into the mobile consumer hardware market, seeking to open up a crypto-native distribution channel for mobile-first applications. The market for Solana Mobile devices has demonstrated a phenomenon whereby external market actors (e.g. Solana-native projects) continuously underwrite subsidies to Mobile consumers. The value of these subsidies, coming in the form of airdrops, trial programs, and exclusive NFT mints, have consistently covered the cost of the phone and generated positive returns for consumers. Given this trend in subsidies, the unit economics in the market for Mobile devices, and the initial growth rate and trajectory of sales, it should be expected that Solana mobile can clear 1M to 10M units over the coming years. As more devices circulate amongst users, Solana Mobile presents a promising venue for the emergence of killer-applications uniquely enabled by this mobile-first, crypto-native distribution channel.

article-image

Mt. Gox has made decent headway with repayments, but they could ramp up from here

article-image

Firm known for crypto hardware wallets set to bring another touchscreen option to consumers

article-image

Plus, BlackRock’s BUIDL is paying out steady yield — and those dividends are growing

article-image

Solana’s biggest liquid staking provider takes a meaningful step towards restaking

article-image

BLAST token skids as Season 2 points plan earns mixed reviews

article-image

Plus, a look at the top asset-gathering ETH ETFs after two days of trading