Solana Exploit: Auditing Firm Claims Ethereum (ETH) Users Also Compromised

Varinder Singh
August 3, 2022
Why Trust CoinGape
CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Solana hack

Solana auditing firm OtterSec in a tweet claimed the Solana (SOL) hack is also affecting Ethereum (ETH) users, although it is less widespread. Until now over 8000 wallets have been compromised. OtterSec said attackers used actual keys for signing transactions, which means private keys on Phantom, Slope, Solflare, and TrustWallet are compromised.

Advertisement
Advertisement

OtterSec Claims Ethereum (ETH) Users Also Affected by Solana Hack

Solana auditing firm OtterSec in a tweet on August 3 said they are tracking the Solana hack. According to a Dune dashboard, over 8000 Solana wallets are now compromised. Moreover, there are incidences of the Solana wallet issue affecting ETH users. However, the ETH users are not widely affected.

The Solana hack affects multiple wallets including Phantom, Slope, Solflare, and TrustWallet. Users are requested to move assets to cold wallets or centralized exchanges.

OtterSec cited an Ethereum user who reported his ERC-20 and USDC-SPL tokens held on both Slope and TrustWallet were drained. Also, the wallets were inactive for 4o days.

PeckShieldAlert also confirmed that a user’s TrustWallet and Slope wallets were compromised on both Solana and Ethereum before the Solana wallets were drained. The attackers transferred nearly $80 million worth of ERC-20 tokens to his Ethereum address.

Moreover, the auditing firm revealed that transactions have been signed by actual owners, which means the private keys were compromised. Solana Labs and Phantom assert their networks are working fine and don’t believe the issue is related to the Solana network or Phantom wallet.

Meanwhile, Solana in the latest tweet confirmed that there is no evidence of hardware wallets being compromised.  Engineers, multiple security researchers, and ecosystem teams are working to identify the root cause of the exploit and track drained wallets on Solana.

“There’s no evidence hardware wallets have been impacted – and users are strongly encouraged to use hardware wallets. Do not reuse your seed phrase on a hardware wallet – create a new seed phrase. Wallets drained should be treated as compromised, and abandoned.”

Solana urges affected users to fill out the “Compromised Wallet Data Collection” form to help engineers look into the issue and find the root cause.

Advertisement
Advertisement

Validator Launches DDOS Attack on Solana

According to Solana validator discord, Jito validator launched a DDOS attack on the Solana RPC nodes to slow down the SOL removal rate from 1000 per minute to 1 per minute.

However, Twitterati questions the DDOS attack on the Solana network. Many claims the attack will continue after the network is up again.

Meanwhile, Solana Labs’ co-founder Anatoly Yakovenko has confirmed the iOS supply chain attack.

Advertisement
coingape google news coingape google news
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Why Trust CoinGape

CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights Read more…to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.

About Author
About Author
Varinder has over 10 years of experience and is known as a seasoned leader for his involvement in the fintech sector. With over 5 years dedicated to blockchain, crypto, and Web3 developments, he has experienced two Bitcoin halving events making him key opinion leader in the space. At CoinGape Media, Varinder leads the editorial decisions, spearheading the news team to cover latest updates, markets trends and developments within the crypto industry. The company was recognized as Best Crypto Media Company 2024 for high impact and quality reporting. Being a Master of Technology degree holder, analytics thinker, technology enthusiast, Varinder has shared his knowledge of disruptive technologies in over 5000+ news, articles, and papers.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.