14 Mar 2025

light mode

Solana exploit. How to protect your SOL and USDC

Solana exploit. How to protect your SOL and USDC

The parable that Solana is in only two aggregate states (either a shutdown or an exploit) will apparently never get old.

As we’ve written earlier, 8,000 user wallets have been robbed for an average of $1000 each.

So, if your SOL and USDC are still on your balance, it’s not your doing – it’s the hackers’ fault. Just kidding, but as we all know, there is truth in every joke. Now, while Solana and white hat hackers collaborate with hacked wallet teams to find vulnerabilities, it makes sense to think about your cybersecurity again.

Let’s try to solve this non-trivial problem with a simple “Given-Find-Solution” scheme. All we need to do is to be sure we know the parameters (“Given”) and to have a clear idea of what result we are interested in (“Find”).


Given:

“a” = Users were robbed in a very brutal way. They didn’t sign anything, didn’t go to phishing sites, and didn’t do any activity. Many of them were sleeping peacefully. That said, the transactions were done, and the blockchain records were legitimate.

“b” = It is already established that no direct hacking of Solana/Ethereum blockchains occurred.

“c” = Some iOS/Android mobile wallets were hacked. For example, hardware wallets like Ledger retained assets. Accounts on centralized exchanges (like FTX or WhiteBIT) were also safe.

“d” = All affected wallets were not active in the last 6 months (that is, it affected HODL’ers and not some noobs). 

“e” = Preliminary investigation showed that the libraries of the corresponding wallets on Github may have been compromised.

“f” = “crypto is not a scam”. We’re not yet ready to become disillusioned with technology in order to go off to grind a blank in a factory and hoard cut-up paper with portraits of dead people for the rest of our lives, which will, in all likelihood, also depreciate.


Find:

A plan where our SOLs and USDCs are always in the place we last put them, regardless of whether the hacker repeats his maneuver.


Solution:

Assuming the hacker repeats his algorithm (and why not repeat it if you’re not in jail yet, there’s $8 million at stake, and you’ve done it before?), the conclusions are as follows:

1. You must move your funds to a place that is known to be safe. As we already know, these can be hardware vaults or secure custodial wallets like blockchain.com wallet.

2. Given that the problem is specific to mobile apps, you should consider switching to browser-based versions of wallets with two-factor authentication.

3. It makes sense to cancel all the automatic confirmations (“ticks”) that you may have recklessly put in any DApps on your phone.

4. HODL is a serious and long-term project that doesn’t go with storage on a smartphone that can freeze, crash, and get lost.


Update

All the teams whose users were affected by the exploit (Solana Labs, Slope, Phantom, Trust Wallet) and several public blockchain engineers have issued their investigations. The only version that remains tentatively proven is a problem on the Slope wallet side.

“The compromised addresses were generated, imported, or used specifically in Slope’s mobile wallet.”

Slope developers have recommended that users immediately transfer the remaining funds to new wallets, making sure to change the seed phrase. However, will this change anything if it is proven that the user’s seed phrases were stored on the wallet’s server? The question is rhetorical.  

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Europeans Are Reluctant to Adopt the Digital Euro

Europeans Are Reluctant to Adopt the Digital Euro

The latest report from the ECB suggests that widespread adoption of the digital euro is far from reality, as most Europeans still prefer conventional payment methods.

Anton Kryshtal
Binance Scores Record-Breaking $2B Investment from Abu Dhabi’s MGX

Binance Scores Record-Breaking $2B Investment from Abu Dhabi’s MGX

The recent $2 billion Binance investment from Abu Dhabi’s MGX marks the single largest investment into a crypto company.

Anahit Avetisyan
Nebraska Enacts New Crypto ATM Regulations: What Will Change?

Nebraska Enacts New Crypto ATM Regulations: What Will Change?

Nebraska has tightened regulations on cryptocurrency ATMs. The new law mandates licensing, sets transaction limits, and requires operators to inform users about potential fraud risks.

Vlad Vovk
Ledger Gives Trezor a Security Boost

Ledger Gives Trezor a Security Boost

Ledger’s security team stepped in to help competitor Trezor fix a major vulnerability in the Safe 3 and Safe 5 models—raising questions about industry-wide security standards.

Anton Kryshtal
Pump.fun’s Meme Coin Frenzy: How It Became a $500M Crypto Powerhouse

Pump.fun’s Meme Coin Frenzy: How It Became a $500M Crypto Powerhouse

In the chaotic world of cryptocurrencies, no platform captures the spirit of financial anarchy better than Pump.fun. What began as an experiment on Solana in early 2024 soon turned into a meme coin explosion.

Ivan Dikalenko
Crypto Voices on Twitter/X: Jack Dorsey Suspended, Hayden Adams Talks DeFi

Crypto Voices on Twitter/X: Jack Dorsey Suspended, Hayden Adams Talks DeFi

A common topic on crypto Twitter (X) today is: ‘Why was Jack Dorsey suspended on the platform he created?’ This leads to another question about the decentralization and control of social media.

Anahit Avetisyan
Crypto Voices on Twitter/X: Michael Saylor’s Speech, BMT Token, and Stables

Crypto Voices on Twitter/X: Michael Saylor’s Speech, BMT Token, and Stables

Crypto moving forward despite market ups and downs. Michael Saylor’s speech on Bitcoin, the launch of Bubblemap’s BMT token, and the growth of stablecoins have been drawing a lot of attention.

Anahit Avetisyan
What Is a Bullish Market? How to Spot One Before It Happens

What Is a Bullish Market? How to Spot One Before It Happens

Learn what a bullish market is, its key characteristics, and how to identify early signs before a full bull market develops. Gain insights into market trends and strategies.

The Coinomist
What Is an MPC? How It Works and Why It Matters

What Is an MPC? How It Works and Why It Matters

Learn about Multi-Party Computation (MPC) in crypto, its mechanics, and benefits. Discover how MPC enhances security, privacy, and decentralized collaboration in digital transactions.

The Coinomist
How to Make Money in Crypto: Top Strategies for Beginners

How to Make Money in Crypto: Top Strategies for Beginners

Discover top strategies to profit in the crypto market—from HODLing and trading to staking, yield farming, NFTs, and crypto lending. Learn the risks and rewards for beginners.

The Coinomist
What Does ATH Mean for Your Crypto Portfolio?

What Does ATH Mean for Your Crypto Portfolio?

Learn what ATH (All-Time High) means for your crypto portfolio, its impact on investor sentiment, and how to strategize around market peaks to manage risk effectively.

The Coinomist
Crypto Heist 101: How Hackers Steal Millions in Crypto

Crypto Heist 101: How Hackers Steal Millions in Crypto

The crypto industry faces massive losses every year from cyberattacks, hacks, and social engineering scams. In 2024 alone, crypto heists resulted in over $2 billion worth of stolen digital assets.

Vlad Vovk
Network Congestion: Key Factors Affecting Your Connection

Network Congestion: Key Factors Affecting Your Connection

Explore the factors that lead to network congestion and learn how high traffic, outdated infrastructure, and interference impact your connection. Find solutions to improve performance.

The Coinomist
Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

It takes just one post from Trump to stir the crypto market. Recently, he announced on Truth Social that the evaluation of a strategic crypto reserve is in progress as part of his broader Trump crypto policy.

Anahit Avetisyan
Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

There’s been a lot of talk about possible changes to crypto tax policies in the U.S. One of the more controversial ideas floating around is “Trump no tax on crypto.” As Trump adopts a more crypto-friendly stance, major rumors have surfaced that he’s considering a 0% tax on crypto gains.

Anahit Avetisyan
MORE
From Lambo Dreams to Tax Nightmares: The Hidden Cost of Crypto Wealth

From Lambo Dreams to Tax Nightmares: The Hidden Cost of Crypto Wealth

Chasing crypto wealth? Don’t let tax obligations drain your profits. We reveal the best ways to lower your tax expenses and keep more of your earnings.

The Coinomist
A Day in the Life of a Web3 Startup Founder: Chaos and Opportunity

A Day in the Life of a Web3 Startup Founder: Chaos and Opportunity

What does a typical day look like for a Web3 founder? Pitching investors, managing internal crises, and trying to stay sane—this and much more in our deep dive.

The Coinomist
MORE