Solana Is Experiencing a Large-Scale Security Incident, What Should You Know?

HuobiPublicado em 2022-08-03Última atualização em 2022-08-05

Resumo

Multiple Solana addresses have succumbed to a widespread attack, as private keys to several wallets have been compromised.

Multiple Solana addresses have succumbed to a widespread attack, as private keys to several wallets have been compromised. Users claim that their wallet funds have been removed without their involvement, more than $8 million worth of SOL, SPL, and other tokens have been siphoned out.

Funds have been transferred to the following 4 addresses:

1:Htp9MGP8Tig923ZFY7Qf2zzbMUmYneFRAhSp7vSg4wxV;

2:CEzN7mqP9xoxn2HdyW6fjEJ73t7qaX9Rp2zyS6hb3iEu;

3:5WwBYgQG6BdErM2nNNyUmQXfcUnB68b6kesxBywh1J3n;

4:GeEccGJ9BEzVbVor1njkBCCiqXJbXVeDHaXDCrBDbmuy.

This article will continue to update:

21:08 UTC (3 August)

Slope Finance declare it will try best to solve &rectify the situation

Slope: No personal data will be stored on centralized servers, internal investigations and audits underway

20:05 UTC (3 August)

Solana Status claims it was Slope who may be responsible for this accident

08:39 UTC (3 August)

Laine repeated that the attack may still underway.

08:26 UTC(3 August)

@aeyakovenko, co-founder of Solana Labs, tweeted that the attack may target on iOS equipments.

07:39 UTC(3 August)

Move to Earn app Walken declare it was back on tack

06:48 UTC(3 August)

StepN declare it move their Treasury fund to cold wallet.

06:37 UTC (3August)

Solana Status invites those impacted to fill out a survey.

06:47 UTC(3 August)

Walken declare it will fail to load at the moment

06:32 ET (3 August)

Alavanche founder Emin Gün Sirer believe the attack was continuing.

05:57 UTC(3 August)

Laine cautioned that this has nothing to do with authorization. They also recommended users to transfer tokens to CEX or Solana CLI.

05:09UST (3 August)

Solana Status claimed to have discovered a vulnerability that allows malicious actors to steal funds from multiple Solana wallets. As of 01:00 today, approximately 7767 wallets were affected.

00:38UST (3 August)

Well-known developer @0xfoobar said that in addition to Phantom, Slope wallet users have also reported theft, and attacker is stealing both native tokens (SOL) and SPL tokens (USDC). @0xfoobar believe it might have been an upstream dependency supply chain attack.

00:38UST (3 August)

Solana Status stated that there is currently no evidence that hardware wallets will be affected, and follow-up information will be released as soon as the investigation progresses.

00:50UST (3 August)

OtterSec confirmed 5000 have been drained, they added: the attacker is signing for the actual keys, meaning it’s not just a delegate issue.

00:33UST (3 August)

STEPN posted an urgent notice of Solana

00:32 UST (3 August)

Phantom, with the largest SOL users, is actively looking for the solution, and they do not believe it is their problem:

00:08 UST (3 August)

Magic Eden warned that there seems to be a widespread SOL exploit at play that's draining wallets throughout the ecosystem

13:13 UTC (3 August)

Solana Status tweeted that engineers from across several ecosystems, in conjunction with audit and security firms, continue to investigate the root cause of an incident that resulted in approximately 8,000 wallets being drained. This does not appear to be a bug with Solana core code, but in software used by several software wallets popular among users of the network.

Leituras Relacionadas

A Guide to Grayscale’s ‘Bottom Fishing’: Using Cash Flow to Assess Cryptocurrency Value

**Title:** Grayscale's Guide to Bottom-Fishing: Valuing Cryptoassets Using Cash Flows **Summary:** This report by Grayscale Research presents a fundamental valuation framework for cryptocurrency assets, moving beyond pure speculation to analyze those with underlying cash flows. It distinguishes between "commodity-like" assets (e.g., Bitcoin) and "cash-flow" assets, primarily within DeFi. Using the leading decentralized lending protocol Aave as a case study, the analysis applies traditional financial methodologies like Discounted Cash Flow (DCF) and Price-to-Earnings (P/E) multiples. Key findings indicate that AAVE tokens are currently undervalued. Despite recent challenges, the protocol's strong revenue growth, ~50% net profit margin, and diversified treasury support a fundamental valuation range of $80-$100 per token (compared to a ~$75 market price at the time of writing). In a base-case scenario driven by stablecoin adoption and regulatory clarity, the fair value could rise to around $175 within a year. The report emphasizes that protocol success does not automatically translate to token value. It critically examines the "value capture" mechanisms—such as buybacks, burns, and staking rewards—that channel protocol profits to token holders. Furthermore, it addresses the legal and governance complexities of Decentralized Autonomous Organizations (DAOs), noting their difference from traditional corporate equity but highlighting how robust, transparent governance can align protocol economics with holder interests. The conclusion is that the crypto market is maturing, with capital increasingly flowing towards projects with demonstrable fundamentals, real adoption, and disciplined capital allocation, creating opportunities for value-based investors.

marsbitHá 10m

A Guide to Grayscale’s ‘Bottom Fishing’: Using Cash Flow to Assess Cryptocurrency Value

marsbitHá 10m

After semiconductors lead the gains, are funds buying into AI orders or a macroeconomic rebound?

After US-Iran talks led to a temporary ceasefire and framework for reopening the strategic Strait of Hormuz, U.S. stocks rose on June 18, with the Nasdaq gaining 1.9%. The semiconductor and AI hardware sectors outperformed. This rally stemmed primarily from reduced geopolitical risk, which lowered oil prices and inflation expectations, easing discount rate pressure on high-valuation growth stocks like tech. The key question is not whether tech rebounded, but the nature of the rebound. The market appears to be selectively repricing AI infrastructure plays rather than broadly chasing AI narratives. Gains were concentrated in chips, optical interconnects, memory, and domestic manufacturing—segments tied to tangible data center build-outs and capital expenditure. Intel's ~10% surge, fueled by a Trump statement about potential Apple collaboration, exemplifies this mixed dynamic. It reflects policy catalysts and domestic manufacturing sentiment more than confirmed fundamentals. Meanwhile, strong earnings from companies like Astera Labs (revenue up 93% YoY) provided concrete evidence of AI-driven demand in hardware. In essence, the rally represents a risk-premium recalibration. Lower Middle East tensions opened a valuation repair window, and capital flowed first into AI infrastructure segments with visible near-term revenue streams. The sustainability of this move hinges on upcoming Q2 earnings, specifically continued strength in cloud provider capex, AI server orders, and hardware company guidance. Policy hopes alone are insufficient; the cycle needs validation from orders and financials.

marsbitHá 15m

After semiconductors lead the gains, are funds buying into AI orders or a macroeconomic rebound?

marsbitHá 15m

The Entire Internet Hails Noam's Joining, But OpenAI's Loss Bill Just Got Thicker

While the AI community celebrates Noam Shazeer, co-author of the "Attention Is All You Need" paper, joining OpenAI as Head of Architectural Research, the company's audited financials reveal a starkly different reality. In 2025, OpenAI reported $13.07 billion in revenue but a massive $20.92 billion operating loss. Even excluding a one-time accounting charge, the cash burn is severe, with $3.7 billion consumed in Q1 2026 alone. This high-profile hiring occurs against a backdrop of significant internal research talent drain, with key founders and researchers departing as the company's focus shifts from exploratory research to product iteration. Meanwhile, OpenAI's fundamental business model faces a deep crisis. It paid Microsoft $10.59 billion for compute in 2025, while its vast user base of 9 billion weekly actives includes only 50 million paying customers, making growth a direct driver of escalating costs. The article argues Shazeer's recruitment is less about technical necessity and more about crafting a compelling narrative for OpenAI's upcoming IPO, aiming to justify a rumored $1 trillion valuation to future public market investors. It contrasts OpenAI's strategy with Anthropic's reported path to profitability, which relies on a strong enterprise customer base and cost control, rather than star-powered narratives. Ultimately, the piece concludes that while Shazeer's architectural work may take 1-2 years to materialize, OpenAI's financial clock is ticking much faster, with its massive losses undercutting the celebratory headlines.

marsbitHá 2h

The Entire Internet Hails Noam's Joining, But OpenAI's Loss Bill Just Got Thicker

marsbitHá 2h

Trading

Spot
Futuros
活动图片