Solana’s Investigation Indicates Wallet Exploit Tied to Slope Mobile App – Altcoins Bitcoin News

0

[ad_1]

Following the Solana wallet attack, the Solana Status team updated the public and detailed that the wallet addresses affected by the breach were tied to Slope mobile wallet applications. The team further stressed that “there is no evidence the Solana protocol or its cryptography was compromised.”

Solana Status Report Says Affected Addresses Were at One Point Created in Slope Mobile Wallet Applications

During the last 48 hours, the Solana team has been dealing with an attack that saw thousands of Solana-based wallets compromised. At the time, Solana Labs co-founder and CEO Anatoly Yakovenko thought the exploit possibly stemmed from a supply chain attack. He explained that iOS and Android wallets were affected when he said: “most of the reports are Slope, but a few Phantom users as well.”

On August 3, 2022, the Solana Status Twitter account explained that the addresses affected in the hack were tethered to Slope mobile wallet applications. “After an investigation by developers, ecosystem teams, and security auditors, it appears affected addresses were at one point created, imported, or used in Slope mobile wallet applications,” Solana Status wrote. “This exploit was isolated to one wallet on Solana, and hardware wallets used by Slope remain secure.” Solana Status said:

While the details of exactly how this occurred are still under investigation, private key information was inadvertently transmitted to an application monitoring service. There is no evidence the Solana protocol or its cryptography was compromised.

Slope Finance published an official statement from the wallet team and breach details are vague. Slope said “A cohort of Slope wallets were compromised in the breach, we have some hypotheses as to the nature of the breach, but nothing is yet firm, [and] we feel the community’s pain, and we were not immune. Many of our own staff and founders’ wallets were drained.” Slope also added that the team was actively conducting internal investigations and audits, while working with security and audit groups.

Security Experts Say Slope’s Seed Phrases Were Logged in Readable Plaintext

During the official statement, the Slope team further recommended that Slope wallet users “create a new and unique seed phrase wallet, and transfer all assets to this new wallet.” Slope added:

If you are using a hardware wallet, your keys have not been compromised.

Data from Dune Analytics shows that there were more unique addresses that were affected by the breach than initially reported. Statistics show that 9,223 unique addresses suffered from the bug and $4,088,121 in crypto was stolen. Most of the assets hacked were made up of solana (SOL) and SOL-based USDC.

It is being said that Slope’s mnemonic seed phrases transferred to Slope’s server were logged in readable text. The Slope wallet team allegedly stored the mnemonics in debug logging software via a centralized Sentry server. Security experts at Ottersec detailed that “anybody with access to Sentry could access [a] user’s private keys.” Ottersec also noted that the Slope team was “very helpful in sharing data related to the hack.”

Tags in this story

altcoin, Altcoins, Anatoly Yakovenko, Dune Analytics, Exploit, Hacker, Hackers, Phantom, Slope, Slope App, Slope Finance, Slope Mobile, Slope Wallet, SOL, SOL wallet hack, SOL-based USDC, Solana, Solana Labs CEO, Solana Labs co-founder, Solana Wallet Exploit, Vulnerability

What do you think about the issues with Slope wallet and the recent exploit that affected Solana users? Let us know your thoughts about this subject in the comments section below.

Jamie Redman

Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,700 articles for Bitcoin.com News about the disruptive protocols emerging today.

Image Credits: Shutterstock, Pixabay, Wiki Commons

Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.

More Popular News

In Case You Missed It

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 85,412.88
ethereum
Ethereum (ETH) $ 2,784.85
tether
Tether (USDT) $ 0.999798
xrp
XRP (XRP) $ 1.97
bnb
BNB (BNB) $ 839.05
usd-coin
USDC (USDC) $ 0.999871
solana
Solana (SOL) $ 128.48
tron
TRON (TRX) $ 0.274432
staked-ether
Lido Staked Ether (STETH) $ 2,774.71
dogecoin
Dogecoin (DOGE) $ 0.140913
cardano
Cardano (ADA) $ 0.405301
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
whitebit
WhiteBIT Coin (WBT) $ 56.66
wrapped-steth
Wrapped stETH (WSTETH) $ 3,390.53
bitcoin-cash
Bitcoin Cash (BCH) $ 551.03
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 85,130.81
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,013.33
usds
USDS (USDS) $ 0.999873
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
leo-token
LEO Token (LEO) $ 9.48
zcash
Zcash (ZEC) $ 536.87
chainlink
Chainlink (LINK) $ 12.23
hyperliquid
Hyperliquid (HYPE) $ 30.62
stellar
Stellar (XLM) $ 0.231379
ethena-usde
Ethena USDe (USDE) $ 0.998992
weth
WETH (WETH) $ 2,781.99
wrapped-eeth
Wrapped eETH (WEETH) $ 3,005.02
monero
Monero (XMR) $ 370.46
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 85,182.82
litecoin
Litecoin (LTC) $ 82.65
avalanche-2
Avalanche (AVAX) $ 13.25
hedera-hashgraph
Hedera (HBAR) $ 0.132550
sui
Sui (SUI) $ 1.36
shiba-inu
Shiba Inu (SHIB) $ 0.000008
dai
Dai (DAI) $ 0.999668
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.20
world-liberty-financial
World Liberty Financial (WLFI) $ 0.150244
usdt0
USDT0 (USDT0) $ 0.999723
uniswap
Uniswap (UNI) $ 6.16
susds
sUSDS (SUSDS) $ 1.08
crypto-com-chain
Cronos (CRO) $ 0.103325
the-open-network
Toncoin (TON) $ 1.53
polkadot
Polkadot (DOT) $ 2.32
paypal-usd
PayPal USD (PYUSD) $ 0.999612
memecore
MemeCore (M) $ 1.98
mantle
Mantle (MNT) $ 0.997365
usd1-wlfi
USD1 (USD1) $ 0.998943
canton-network
Canton (CC) $ 0.076316
bittensor
Bittensor (TAO) $ 273.93
c1usd
Currency One USD (C1USD) $ 1.01
Shares