Solana Wallets Compromised In Multimillion-Dollar Hack

cryptodaily发布于2022-08-03更新于2022-08-04

文章摘要

Now news has emerged that several hackers have targeted the Solana ecosystem, and losses are nearing the billion-dollar mark.

2022 looks set to be one of the worst years for the crypto markets, which were already dealing with significant bear market sentiment. Now news has emerged that several hackers have targeted the Solana ecosystem, and losses are nearing the billion-dollar mark.

Thousands of users have reported that their funds have been drained from their hot wallets without their knowledge.

An Unprecedented Attack

Thousands of users took to Twitter to report their SOL being stolen from connected hot wallets such as Phantom, Slope, and TrustWallet. With the attack still ongoing, details remain sketchy, but over 8000 wallets have been compromised, according to data sourced from blockchain auditors OtterSec. Several Solana addresses have been linked to the ongoing attack, with the wallets in question amassing millions worth of SOL, SPL, and other Solana-based tokens drained from unsuspecting wallets.

UPDATE: Over 8,000 #Solana wallets have fallen victim to the ongoing hack, with more increasing by the minute.”

Details Remain Sketchy

The exact cause of the attack remains unknown at present, although community members are scrambling to trace the source of the attack. However, what is clear is that the attack seems to have impacted mobile wallet users the most, with the attacker somehow managing to sign transactions on behalf of users and wallet owners. This suggests that there could be a third-party service that could have been compromised in a supply-chain attack.

The private-key exploit resulted in the hacker stealing native SOL and SPL tokens from hot wallets, most of which had been inactive for more than six months, with Phantom and Slope wallet users being hit the hardest. Twitter user foobar shed some light on the methodology used by the attackers, stating that while the cause of the exploit was unknown, it could be the result of an upstream dependency supply chain attack. He also stated that revoking prior approvals would not help ensure the security of the funds, adding that the only viable option was moving funds to an offline wallet. However, if a hardware wallet is not an option, users can also shift their assets to a reliable centralized exchange for the time being.

Solana Community Reacts

The attack will undoubtedly reignite the debate around hot wallets and their security. Hot wallets are connected to the internet at all times, and while this does ensure some convenience, allowing users to send, receive, and store crypto with ease, it is also susceptible to attacks. Cold wallets, which are offline and must be connected to a device to carry out transactions, are considered much more secure.

While the concerned parties are looking into the exploit, worried users reached out to wallet providers for an update and clarity on the source of the attack. Phantom did provide users an update on Twitter, stating that it was working to figure out the cause of the attack.

“We are working closely with other teams to get to the bottom of a reported vulnerability in the Solana ecosystem. At this time, the team does not believe this is a Phantom-specific issue. As soon as we gather more information, we will issue an update.”

Other community members speculated that the exploit could be related to Magic Eden’s Solana-based NFT marketplace, although this link remained doubtful as the attack continued. So far, Magic Eden has not commented on the situation but did tweet out a warning, advising users to revoke permissions from the wallet and move assets to a cold wallet.

“There seems to be a widespread SOL exploit at play that’s draining wallets throughout the ecosystem Here’s what you can do right now to best protect yourself 1. Go to >Settings on your @phantom wallet 2. >Trusted Apps 3. >Revoke Permissions for any suspicious links.”

In a later tweet, it added that it was looking into the exploit to determine its cause.

Solana Price Feels The Pressure

Currently, the primary discourse across crypto Twitter remains around mitigating the damage from the exploit, with experts urging users to transfer their assets to a cold wallet. Solana’s price has also dropped significantly over the past few hours and is down considerably. While the price has recovered from its initial slump, it could drop again as the attack plays out.

A History Of Outages

The Solana ecosystem has had a torrid 2022, with regular outages plaguing the “Ethereum Killer.” In January, Solana crashed for a staggering 48 hours, forcing users to liquidate their holdings and fulfill their loan obligations. The outage was caused due to bots spamming the network, leading to significant congestion on the network, which led to the outage. As a result, DeFi users were unable to top up their loan collateral, forcing them to liquidate their holdings.

你可能也喜欢

对话投资人郑迪:微策略卖币实验、AI经济和美股机遇

前沿科技投资人郑迪(didier)在访谈中分析了近期比特币下跌、微策略财务策略、AI经济影响及美股机遇等话题。 郑迪认为,比特币近期下跌的核心原因并非单纯宏观因素或ETF赎回,而是市场开始预期微策略(MicroStrategy)在“每股含币量中性”原则下,为支付优先股股息可能持续小额卖出比特币。这引发了市场对持续抛压的担忧,导致相关资金提前撤离。他认为,微策略创始人Michael Saylor正在测试市场对持续小额卖币的承接能力,这是一场与市场的博弈。但单凭此事不太可能引发“死亡螺旋”,后续若无重大利空,局面有望扭转。 关于AI驱动的美股上涨,郑迪指出,其核心驱动力在于Token(代币)正成为新时代的“劳动力”。AI和Token正在替代许多传统由人执行的工作,企业未来会将更多预算分配给Token、模型和算力,从而提升效率和利润率。这推动了上游芯片、光模块、数据中心等美股产业链的持续上涨,标志着机器经济时代的开始,具有中长期持续性。 针对加密交易所接入美股的现象,郑迪认为这是行业发展的自然趋势。由于真正有价值的加密原生资产有限,交易所转向美股等真实世界资产是寻找更具流动性标的的选择。这并不一定挤压加密资产,长期看,区块链技术为真实资产上链和未来的机器经济提供了基础设施,反而可能利好比特币。对于从加密市场转向美股的交易者,郑迪建议无需刻意改变交易逻辑,因为美股中同样存在类似山寨币的meme属性资产或价值成长股,可以找到熟悉的风格。 郑迪提到,“1011事件”对加密行业流动性造成重创,大量现金损失是压垮山寨币行情的最后一根稻草,相关炒作热情已转移至流动性更好的美股市场。 对于宏观前景,郑迪对下半年持更谨慎态度,因市场上涨后不确定性增加,且巨型公司(如SpaceX)上市可能带来流动性压力。中期选举结果也可能影响Web3和AI领域的政策环境。长期来看,他依然看好AI对生产率的提升以及AI与区块链的结合,认为未来将进入更产业化、机构化的阶段,但需关注技术带来的社会分配问题。

marsbit24分钟前

对话投资人郑迪:微策略卖币实验、AI经济和美股机遇

marsbit24分钟前

灰度抄底指南:利用现金流评估加密货币价值

本文探讨了在加密货币市场下跌背景下,如何利用现金流评估加密资产价值,并以去中心化借贷协议Aave为例进行深入分析。 核心观点认为,并非所有加密资产都适用相同估值方法。像比特币这类“类商品资产”依赖稀缺性和共识,而许多DeFi代币等“现金流资产”则与协议业务活动绑定,可通过分析协议收入、利润及代币价值捕获机制来估值。 报告指出,DeFi已成为能产生持续真实收入的赛道。Aave作为头部借贷协议,财务数据透明,拥有多元收入来源和雄厚国库。通过现金流折现(DCF)分析和与传统金融科技公司(市盈率约20-25倍)对比,灰度研究部认为AAVE代币当前合理估值区间为80-100美元(现价约75美元)。报告还预测,在监管明确化等利好情景下,其一年内价值可能升至约175美元。 文章强调,代币价值捕获机制至关重要,即协议如何将利润回馈给代币持有者(如回购、分红)。Aave通过治理演进,正加强协议经济与代币价值的绑定。同时,DAO的法律地位与监管政策(如《CLARITY法案》)仍是影响估值的关键不确定因素。 最后,报告认为市场正趋于成熟,资金从炒作项目流向具备实质收入、清晰商业模式和基本面的资产。投资者应关注如Aave、Uniswap等真正创造现金流的协议,运用基本面分析发现投资机会。

marsbit2小时前

灰度抄底指南:利用现金流评估加密货币价值

marsbit2小时前

交易

现货
合约
活动图片