Solana x Slope Exploit Thread
Screenshot of Dune Analytics Dashboard w data pertaining to Solana x Slope exploit

Solana x Slope Exploit Thread

Update 6:30 PM CT: Zach Dhihan gives advice to users who want to keep using their Slope Wallets.

No alt text provided for this image

Update 4:20 PM CT: Zach Dhihan officially gives recommendation that users who imported wallet accounts into slope to regenerate new seed phrases for those accounts asap.

No alt text provided for this image
No alt text provided for this image

Update 3:30 PM CT: Solana Labs issues an official response.

No alt text provided for this image

Update 3:00 PM CT:?Slope Finance?issues an initial official statement

No alt text provided for this image

Update 12:45 PM CT:?Anatoly Yakovenko?confirms with another researcher,?Adam Cochran, his observation that?Slope Finance?seems to be the common denominator in the attack.

No alt text provided for this image


Update 5:00 AM CT:?Anatoly Yakovenko,?#Solana?Co-founder, is all but confirming this is a iOS/Android level supply chain attack.

No alt text provided for this image

Original Post:

Ok, so yesterday afternoon?#Solana?wallets started getting drained. Other tokens such as?#USDC?were drained as well.?As of writing this over $1.7 Million (USD) worth of Solana was drained out of almost 8000 unique wallets.

No alt text provided for this image

https://dune.com/brownboy/solana-hack/?

The current resounding theory is that mobile users have their private keys/phrases cached on the phone as a JSON file (.env file) and that is somehow being exploited due to malware in the source code of the wallets themselves.?

The exploit seems to have mainly affected iOS devices, but some android devices were exploited as well.?Phantom,?Trust Wallet, and?Slope Finance?wallets across mobile and browser extensions were affected.?

There are a handful of?#whitehat?hackers who were able to trace the IP of the attackers to Moldova by sending self-hosted NFTs - with some fancy code tucked in - to the attackers' wallets and then waited for them to open the NFTs in?Phantom. After doing that the server hosting the NFTs was able to scrape the data to get the IP and browser information.?

No alt text provided for this image

I’ll keep covering this story as it evolves.?

Dave Heavyside

A mind that never sleeps.

2 年

Amazing efforts on this Dennis. ??????

要查看或添加评论,请登录

Dennis Layden的更多文章

  • What's Going On In Web3 | Feb 7, 2023

    What's Going On In Web3 | Feb 7, 2023

    GM whats up, long time no talk! It's been a while since I wrote here. To be honest, I got burnt out from writing…

    3 条评论
  • What's Going On In Web3 | October 20, 2022

    What's Going On In Web3 | October 20, 2022

    gm, here's yesterday's headlines you might have missed. Curated and threaded by @d3layd with care ?? Wanna talk about…

  • What's Going On In Web3 | October 19, 2022

    What's Going On In Web3 | October 19, 2022

    Here’s the headlines you probably missed from yesterday, and a few from this morning. We’ll be talking about this and…

    1 条评论
  • What's going on in web3 | October 18, 2022

    What's going on in web3 | October 18, 2022

    gm, here's the web3 news you might have missed yesterday/this morning. Before you get into the news, I wanted to tell…

    1 条评论
  • What’s Going On In Web3 | October 7, 2022

    What’s Going On In Web3 | October 7, 2022

    Binance Smart Chain Gets Hacked, Losses 100M Last night the Binance Smart Chain was hacked and the attacker was able to…

  • What's Going On In Web3 | Issue # 15

    What's Going On In Web3 | Issue # 15

    Sorry for the delay, it’s been a busy few weeks with me and I’ve missed you guys a ton. Thanks for being patient with…

  • What's Goin On In Web3? Issue #14 | August 10, 2022

    What's Goin On In Web3? Issue #14 | August 10, 2022

    GM here's a recap of the biggest headlines in web3 over the last few days and a bit of a breakdown for you. Please DM…

  • What’s going on in web3? Issue #13 | Friday, August 5, 2022

    What’s going on in web3? Issue #13 | Friday, August 5, 2022

    GM! I wasn’t able to post yesterday but there wasn’t a need to at the end of the day following the Solana x Slope…

  • What's going on in Web3? Issue #12 | August 3, 2022

    What's going on in Web3? Issue #12 | August 3, 2022

    GM, yesterday we saw a HUGE #Solana exploit (still ongoing as of publishing this), a Gucci & ApeCoin collab, Magic Eden…

    6 条评论
  • What's going on in web3? Issue #11 | August 2, 2022

    What's going on in web3? Issue #11 | August 2, 2022

    Ledger seeks 100M in funding According to Bloomberg, Ledger is seeking another 100 Million in funding following a…

社区洞察

其他会员也浏览了