Solana Is Experiencing a Large-Scale Security Incident, What Should You Know?

HuobiPubblicato 2022-08-03Pubblicato ultima volta 2022-08-05

Introduzione

Multiple Solana addresses have succumbed to a widespread attack, as private keys to several wallets have been compromised.

Multiple Solana addresses have succumbed to a widespread attack, as private keys to several wallets have been compromised. Users claim that their wallet funds have been removed without their involvement, more than $8 million worth of SOL, SPL, and other tokens have been siphoned out.

Funds have been transferred to the following 4 addresses:

1:Htp9MGP8Tig923ZFY7Qf2zzbMUmYneFRAhSp7vSg4wxV;

2:CEzN7mqP9xoxn2HdyW6fjEJ73t7qaX9Rp2zyS6hb3iEu;

3:5WwBYgQG6BdErM2nNNyUmQXfcUnB68b6kesxBywh1J3n;

4:GeEccGJ9BEzVbVor1njkBCCiqXJbXVeDHaXDCrBDbmuy.

This article will continue to update:

21:08 UTC (3 August)

Slope Finance declare it will try best to solve &rectify the situation

Slope: No personal data will be stored on centralized servers, internal investigations and audits underway

20:05 UTC (3 August)

Solana Status claims it was Slope who may be responsible for this accident

08:39 UTC (3 August)

Laine repeated that the attack may still underway.

08:26 UTC(3 August)

@aeyakovenko, co-founder of Solana Labs, tweeted that the attack may target on iOS equipments.

07:39 UTC(3 August)

Move to Earn app Walken declare it was back on tack

06:48 UTC(3 August)

StepN declare it move their Treasury fund to cold wallet.

06:37 UTC (3August)

Solana Status invites those impacted to fill out a survey.

06:47 UTC(3 August)

Walken declare it will fail to load at the moment

06:32 ET (3 August)

Alavanche founder Emin Gün Sirer believe the attack was continuing.

05:57 UTC(3 August)

Laine cautioned that this has nothing to do with authorization. They also recommended users to transfer tokens to CEX or Solana CLI.

05:09UST (3 August)

Solana Status claimed to have discovered a vulnerability that allows malicious actors to steal funds from multiple Solana wallets. As of 01:00 today, approximately 7767 wallets were affected.

00:38UST (3 August)

Well-known developer @0xfoobar said that in addition to Phantom, Slope wallet users have also reported theft, and attacker is stealing both native tokens (SOL) and SPL tokens (USDC). @0xfoobar believe it might have been an upstream dependency supply chain attack.

00:38UST (3 August)

Solana Status stated that there is currently no evidence that hardware wallets will be affected, and follow-up information will be released as soon as the investigation progresses.

00:50UST (3 August)

OtterSec confirmed 5000 have been drained, they added: the attacker is signing for the actual keys, meaning it’s not just a delegate issue.

00:33UST (3 August)

STEPN posted an urgent notice of Solana

00:32 UST (3 August)

Phantom, with the largest SOL users, is actively looking for the solution, and they do not believe it is their problem:

00:08 UST (3 August)

Magic Eden warned that there seems to be a widespread SOL exploit at play that's draining wallets throughout the ecosystem

13:13 UTC (3 August)

Solana Status tweeted that engineers from across several ecosystems, in conjunction with audit and security firms, continue to investigate the root cause of an incident that resulted in approximately 8,000 wallets being drained. This does not appear to be a bug with Solana core code, but in software used by several software wallets popular among users of the network.

Letture associate

Playnance’s $GCOIN Lists on KoinBX Amid Rapid Growth in India

Playnance's native token, $GCOIN, has been listed on the cryptocurrency exchange KoinBX as of June 18. This move aims to enhance accessibility for its rapidly growing community, particularly in India, where the blockchain-powered Web3 iGaming ecosystem has gained significant traction. Over 130 partners in Playnance's "Be the Boss" program have built communities engaging thousands of active players in the region. The "Be the Boss" model allows participants to create and manage their own gaming communities, earning rewards tied to community activity. CEO Pini Peter noted India's high engagement, with community leaders successfully building player networks. One partner, Dr. Nicolas, reported earning over $57,000 through the program in recent months, highlighting both the financial rewards and the opportunity to grow an engaged community. $GCOIN serves as the ecosystem's core utility token, incentivizing participation and aligning the interests of players and community leaders ("Bosses"). The listing on KoinBX is part of Playnance's strategy to expand globally, increasing the token's utility and accessibility by combining community ownership, gamified engagement, and blockchain-based incentives. Founded in 2020, Playnance is a Web3 iGaming infrastructure company focused on creating live, non-custodial, on-chain products to onboard mainstream users. It currently processes approximately one million transactions daily, aiming to simplify the user experience while maintaining full on-chain transparency.

TheNewsCrypto40 min fa

Playnance’s $GCOIN Lists on KoinBX Amid Rapid Growth in India

TheNewsCrypto40 min fa

STRC Hits Historic Low, Saylor's Perpetual Motion Machine Grinds to a Halt

STRC, the perpetual preferred stock issued by MicroStrategy to fund its Bitcoin purchases, hit a historic low of $85.32, a 17% discount to its $100 par value. Designed as a "digital credit engine" to trade stably near par and enable continuous share issuance for buying Bitcoin, its plunge signals a breakdown in this model. Three key factors drove the decline: 1. Bitcoin's price fell over 50% from its peak, trading around $63,000 amid hawkish Fed signals. 2. MicroStrategy's cash reserves were depleted after a $1.5 billion convertible note repayment, slashing the dividend coverage for STRC's 11.5% yield to ~7 months. The company then sold 32 BTC to cover dividends—Michael Saylor's first Bitcoin sale since 2022—damaging the "never sell" narrative. 3. A competing Bitcoin-backed preferred stock, Strive's SATA, offers a higher yield (~13%) and daily dividends, drawing investors away from STRC. The drop triggers a negative cycle: STRC below par halts ATM share issuances, cutting off a key funding source for Bitcoin buys and potentially forcing more BTC sales for dividends, further eroding confidence. While Saylor argues the model is mathematically sound—needing only 2.3% annual Bitcoin growth to sustain itself—the market is testing the resilience of the leveraged Bitcoin treasury strategy in a bear market. The STRC price now reflects rising skepticism about this financial machinery's durability during downturns.

marsbit1 h fa

STRC Hits Historic Low, Saylor's Perpetual Motion Machine Grinds to a Halt

marsbit1 h fa

A Guide to Grayscale’s ‘Bottom Fishing’: Using Cash Flow to Assess Cryptocurrency Value

**Title:** Grayscale's Guide to Bottom-Fishing: Valuing Cryptoassets Using Cash Flows **Summary:** This report by Grayscale Research presents a fundamental valuation framework for cryptocurrency assets, moving beyond pure speculation to analyze those with underlying cash flows. It distinguishes between "commodity-like" assets (e.g., Bitcoin) and "cash-flow" assets, primarily within DeFi. Using the leading decentralized lending protocol Aave as a case study, the analysis applies traditional financial methodologies like Discounted Cash Flow (DCF) and Price-to-Earnings (P/E) multiples. Key findings indicate that AAVE tokens are currently undervalued. Despite recent challenges, the protocol's strong revenue growth, ~50% net profit margin, and diversified treasury support a fundamental valuation range of $80-$100 per token (compared to a ~$75 market price at the time of writing). In a base-case scenario driven by stablecoin adoption and regulatory clarity, the fair value could rise to around $175 within a year. The report emphasizes that protocol success does not automatically translate to token value. It critically examines the "value capture" mechanisms—such as buybacks, burns, and staking rewards—that channel protocol profits to token holders. Furthermore, it addresses the legal and governance complexities of Decentralized Autonomous Organizations (DAOs), noting their difference from traditional corporate equity but highlighting how robust, transparent governance can align protocol economics with holder interests. The conclusion is that the crypto market is maturing, with capital increasingly flowing towards projects with demonstrable fundamentals, real adoption, and disciplined capital allocation, creating opportunities for value-based investors.

marsbit2 h fa

A Guide to Grayscale’s ‘Bottom Fishing’: Using Cash Flow to Assess Cryptocurrency Value

marsbit2 h fa

After semiconductors lead the gains, are funds buying into AI orders or a macroeconomic rebound?

After US-Iran talks led to a temporary ceasefire and framework for reopening the strategic Strait of Hormuz, U.S. stocks rose on June 18, with the Nasdaq gaining 1.9%. The semiconductor and AI hardware sectors outperformed. This rally stemmed primarily from reduced geopolitical risk, which lowered oil prices and inflation expectations, easing discount rate pressure on high-valuation growth stocks like tech. The key question is not whether tech rebounded, but the nature of the rebound. The market appears to be selectively repricing AI infrastructure plays rather than broadly chasing AI narratives. Gains were concentrated in chips, optical interconnects, memory, and domestic manufacturing—segments tied to tangible data center build-outs and capital expenditure. Intel's ~10% surge, fueled by a Trump statement about potential Apple collaboration, exemplifies this mixed dynamic. It reflects policy catalysts and domestic manufacturing sentiment more than confirmed fundamentals. Meanwhile, strong earnings from companies like Astera Labs (revenue up 93% YoY) provided concrete evidence of AI-driven demand in hardware. In essence, the rally represents a risk-premium recalibration. Lower Middle East tensions opened a valuation repair window, and capital flowed first into AI infrastructure segments with visible near-term revenue streams. The sustainability of this move hinges on upcoming Q2 earnings, specifically continued strength in cloud provider capex, AI server orders, and hardware company guidance. Policy hopes alone are insufficient; the cycle needs validation from orders and financials.

marsbit2 h fa

After semiconductors lead the gains, are funds buying into AI orders or a macroeconomic rebound?

marsbit2 h fa

Trading

Spot
Futures
活动图片