Solana denies ‘security threat’ to Saga phones following CertiK video

In a statement to Blockworks, Solana denied a “vulnerability” to Saga phone holders from CertiK

article-image

Solana modified by Blockworks

share

CertiK, on Wednesday, claimed that it found a vulnerability with the Solana Saga phone.

Saga is an Android device — the first being offered by Solana.

The auditor said in a post on X that the phone has a bootloader vulnerability. Essentially, a backdoor can supposedly be installed on the phone allowing the initial software responsible for the starting of the device to be compromised. 

“The boot loader is unlocked and software integrity cannot be guaranteed. Any data stored on the device may be available to attackers, Do not store any sensitive data on the device,” a screengrab from CertiK’s accompanying video shows the Solana phone’s screen following the backdoor install.

The message is an indication that the phone has been hacked, CertiK said. However, it’s not clear if the vulnerability is unique to Saga or if it could impact other Android devices. CertiK did not immediately respond to a request for comment.

Loading Tweet..

In an email to Blockworks, Steven Laver, lead software engineer of mobile at Solana Labs said that “the CertiK video does not reveal any known vulnerability or security threat to Saga holders. The video shows the user unlocking the bootloader, which is something that can be done on many Android devices.” 

Android’s own documentation from its Open Source Project outlines the ability to lock and unlock the bootloader. 

“Unlocking the bootloader is an advanced feature of Saga, and is disabled by default. We believe in allowing users the choice of how they use their phone, however, unlocking the bootloader is not a security vulnerability – a user must explicitly allow such changes to be made to their device, and those changes can only be made by an authorized user of the phone,” Laver continued.

However, if a user or attacker proceeds to unlock the bootloader, then they not only go through multiple warnings, but their device is wiped — along with their private keys.

“So it’s not a process that can take place without users’ active participation or awareness,” Laver said. 

CertiK, however, said that only being able to unlock the bootloader with user participation “does not eliminate all potential threats.”

“Malicious actors can purchase Saga phones and install backdoors through such ‘feature,’ and deliver devices to unconscious users. If users did not understand the warnings, they would be tricked and lose funds to attackers,” CertiK said in an email to Blockworks.

“In addition, given the fact that a considerable portion of traditional phone users have taken the initiative to jailbreak or unlock their devices in the past, it is also likely that some Saga phone users will also explore this “feature” but without enough security awareness. That’s why we warn users about such situations in our video.”

The video then proceeds to show how an attacker could drain bitcoin from the wallet attached to the phone. It did not show Seed Vault being used in the video, which protects both supported digital assets and seeds. 

Seed Vault was announced in June 2022, and “accesses the highest privileged security environment available on a device, from secure operating modes of the processor to dedicated Secure Elements, which enables a secure transaction signing experience through UI components built into Android.”

Saga was released in April, having been designed to pair Web3 with smartphones. Alongside traditional app stores, Solana offers a separate app store.

The phone is designed to allow users to have “self-custody of their assets” to make them “feel comfortable bringing those assets with them on the go,” Laver told Blockworks when the phone was released. 

Months after the launch, the price of Saga was reduced to $599 from $1,000 — a 40% cut.

At the time, Emmett Hollyer, head of business operations for Solana Mobile, told Blockworks that the price reduction is “common practice in the consumer electronics business, particularly with smartphones.”

According to CoinMarketCap, the vulnerability has not impacted SOL — Solana’s native crypto — at the time of publishing. In fact, it’s up more than 13% over the past day.

Updated Friday, Nov. 17 at 12:15 pm ET: Added comment from CertiK.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

recent research

Research Report Templates (19).png

Research

Suilend has grown into the top money market and liquid staking provider on Sui. STEAMM, Suilend’s Superfluid AMM, presents a compelling avenue for growing market share within Sui’s DEX landscape and revenue generation for the protocol. Suilend’s multi-product suite position it well for owning market share across key verticals. While current metrics across the Sui ecosystem are likely inflated due to Sui Foundation incentive programs, SEND trades at amongst the lowest multiples in the lend/borrow sector, suggesting that a bull case for continued growth in the ecosystem may be mispriced.

article-image

Silk Road founder Ulbricht made a triumphant return to the Bitcoin Conference, 10 years on from sentencing

article-image

A Blockworks Research report looked at who could take up some of the marketshare in the launchpad space

article-image

Business-to-business stablecoin payments are on the rise, per a report from Artemis, Dragonfly and Castle Island

article-image

Crypto continues to do its thing: incentivizing behavior

article-image

Kraken will soon offer Backed ‘xStocks’ as Solana tokens

article-image

In a unanimous decision, the US Court of International Trade has ruled that Trump’s IEEPA tariffs are unlawful