Solana Faces Security Threat as Blowfish Detects Drainer Risk

Kelvin Munene Murithi
February 10, 2024
Why Trust CoinGape
CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Solana

Highlights

  • Aqua and Vanish exploit Solana's dApps, flipping transaction conditions post-approval.
  • Chainalysis reports over 6,000 members in a Solana wallet drainer kit community.
  • Blowfish's automated defenses combat Solana drainers while tracking on-chain activity.

Web3 security firm Blowfish has recently discovered two new types of Solana drainers, ‘Aqua’ and ‘Vanish.’ These harmful programs can be exploited to steal users’ cryptocurrency by modifying the transaction conditions even after the users’ private keys have approved the transaction. This revelation signifies the increasing complexity of cyber threats in the blockchain environment and the necessity of improved security mechanisms.

Advertisement
Advertisement

Surge In Solana Drainers

The discovery of Aqua and Vanish has sounded the alarm within the Solana network, as these drainers work by utilizing the authority granted to decentralized applications (dApps) to submit transactions on behalf of users. 

Through the change of a conditional in the transaction data, these drainers are capable of switching from sending to draining SOL from the account of the victimized user. This bit-flip attack method, which involves modifying the value of bits within encrypted data to affect the outcome of transactions, has become a deadly weapon in the hands of hackers focusing on the Solana network.

Advertisement
Advertisement

The Spread of Scam-as-a-Service

Blowfish’s investigation shows that Aqua and Vanish scripts are being sold in SaaS (scam-as-a-service) tool marketplaces, which makes it possible for the threat actor to run these stealers without deep technical expertise. 

The commercialization of cybercrime tools has led to a rise in the number of attacks aimed at cryptocurrency users, with Solana becoming the primary target alongside its growing popularity. According to Chainalysis, a considerable community is formed for a Sellana wallet drainer kit consisting of over 6,000 people, illustrating the ubiquitous nature of the threat.

Advertisement
Advertisement

Drainer Dangers Prevention Efforts

In reply to the detection of Aqua and Vanish, Blowfish has deployed defenses designed to thwart these two drainers automatically and is closely tracking on-chain activity for suspicious activities. Nevertheless, the difficulty remains considerable since threat actors always develop new techniques and ways to avoid security measures. 

The participation of Russian developers in the creation and distribution of these drainers, which usually have Russian documentation attached, gives an international angle to the cybersecurity problems of the Solana community.

Additionally, the wider blockchain security community is gathering to confront this emerging danger. In this respect, Wallet Guard is designed for users who wish to defend themselves against such attacks since the latter usually starts with phishing attempts. By leveraging social engineering techniques, the attackers attract victims to fake DeFi platforms that look like legitimate ones and prompt them to approve malicious transactions.

Read Also: Bitcoin (BTC) Addresses in Profit Tops 90% as Price Eyes $50K

Advertisement
coingape google news coingape google news
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Why Trust CoinGape

CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights Read more…to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.

About Author
About Author
Kelvin Munene is a crypto and finance journalist with over 5 years of experience, offering in-depth market analysis and expert commentary . With a Bachelor's degree in Journalism and Actuarial Science from Mount Kenya University, Kelvin is known for his meticulous research and strong writing skills, particularly in cryptocurrency, blockchain, and financial markets. His work has been featured across top industry publications such as Coingape, Cryptobasic, MetaNews, Cryptotimes, Coinedition, TheCoinrepublic, Cryptotale, and Analytics Insight among others, where he consistently provides timely updates and insightful content. Kelvin’s focus lies in uncovering emerging trends in the crypto space, delivering factual and data-driven analyses that help readers make informed decisions. His expertise extends across market cycles, technological innovations, and regulatory shifts that shape the crypto landscape. Beyond his professional achievements, Kelvin has a passion for chess, traveling, and exploring new adventures.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.