Solana mobile wallet exploited, millions removed from over 8,000 users
Categories: Crypto News US
Solanamobile wallet exploited, millions removed from over 8,000 users
No evidence was found that the Solana protocol or itscryptography was compromised, nor were its hardware wallets. According to aSolana status tweet, engineers from several ecosystems, along with audit andsecurity firms, were continuing to investigate the "root cause" ofthe attack.
Blockchain investigation firm PeckShield posted on August 2that the hack was most likely due to a "supply chain problem,"which was used to steal the private keys of the users behind the affectedwallets. The exact cause of the attack is unclear, although it appears thatmobile wallet users were most affected. The attackers were able to signtransactions on behalf of users, suggesting that a trusted third-party servicemay have been compromised.
The Solana Status Twitter account shared its preliminaryfindings through developers and security auditors, saying that "itappears that the affected addresses were at one point created, imported or usedin Slope mobile wallet applications". The thread continued: "Thisexploit was isolated to a wallet on Solana, and the hardware wallets used bySlope remain secure.
While the details of how this happened are still underinvestigation, private key information was inadvertently transmitted to anapplication monitoring service." Over the past nine months, Solana hasbeen blamed for "extremely duplicate transactions" and "high-levelcongestion".
Due to some serious downtime has been encountered on mynetwork.It also suffered a distributed denial-of-service attack in Decemberlast year that jammed the network and caused huge delays, leading many toquestion the security of the network.