13 Jan 2025

Solana exploit. How to protect your SOL and USDC

Solana exploit. How to protect your SOL and USDC

The parable that Solana is in only two aggregate states (either a shutdown or an exploit) will apparently never get old.

On this page

As we’ve written earlier, 8,000 user wallets have been robbed for an average of $1000 each.

So, if your SOL and USDC are still on your balance, it’s not your doing – it’s the hackers’ fault. Just kidding, but as we all know, there is truth in every joke. Now, while Solana and white hat hackers collaborate with hacked wallet teams to find vulnerabilities, it makes sense to think about your cybersecurity again.

Let’s try to solve this non-trivial problem with a simple “Given-Find-Solution” scheme. All we need to do is to be sure we know the parameters (“Given”) and to have a clear idea of what result we are interested in (“Find”).


Given:

“a” = Users were robbed in a very brutal way. They didn’t sign anything, didn’t go to phishing sites, and didn’t do any activity. Many of them were sleeping peacefully. That said, the transactions were done, and the blockchain records were legitimate.

“b” = It is already established that no direct hacking of Solana/Ethereum blockchains occurred.

“c” = Some iOS/Android mobile wallets were hacked. For example, hardware wallets like Ledger retained assets. Accounts on centralized exchanges (like FTX or WhiteBIT) were also safe.

“d” = All affected wallets were not active in the last 6 months (that is, it affected HODL’ers and not some noobs). 

“e” = Preliminary investigation showed that the libraries of the corresponding wallets on Github may have been compromised.

“f” = “crypto is not a scam”. We’re not yet ready to become disillusioned with technology in order to go off to grind a blank in a factory and hoard cut-up paper with portraits of dead people for the rest of our lives, which will, in all likelihood, also depreciate.


Find:

A plan where our SOLs and USDCs are always in the place we last put them, regardless of whether the hacker repeats his maneuver.


Solution:

Assuming the hacker repeats his algorithm (and why not repeat it if you’re not in jail yet, there’s $8 million at stake, and you’ve done it before?), the conclusions are as follows:

1. You must move your funds to a place that is known to be safe. As we already know, these can be hardware vaults or secure custodial wallets like blockchain.com wallet.

2. Given that the problem is specific to mobile apps, you should consider switching to browser-based versions of wallets with two-factor authentication.

3. It makes sense to cancel all the automatic confirmations (“ticks”) that you may have recklessly put in any DApps on your phone.

4. HODL is a serious and long-term project that doesn’t go with storage on a smartphone that can freeze, crash, and get lost.


Update

All the teams whose users were affected by the exploit (Solana Labs, Slope, Phantom, Trust Wallet) and several public blockchain engineers have issued their investigations. The only version that remains tentatively proven is a problem on the Slope wallet side.

“The compromised addresses were generated, imported, or used specifically in Slope’s mobile wallet.”

Slope developers have recommended that users immediately transfer the remaining funds to new wallets, making sure to change the seed phrase. However, will this change anything if it is proven that the user’s seed phrases were stored on the wallet’s server? The question is rhetorical.  

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author

Latest News

MORE
The Future of Crypto in 2025: Fidelity’s Predictions

The Future of Crypto in 2025: Fidelity’s Predictions

What’s next for the biggest cryptocurrencies in 2025? Fidelity Digital Assets analyst Chris Kuiper shares insights on how Bitcoin will navigate volatility, Ethereum will address scaling challenges, and stablecoins will adapt to evolving regulations.

13 Jan 2025
The Crypto Rollercoaster of 2024 — Wins and Woes

The Crypto Rollercoaster of 2024 — Wins and Woes

The crypto sector evolved at breakneck speed in 2024. With major wins and notable setbacks, it’s time to reflect on the year’s key developments and their implications for the future.

31 Dec 2024
OpenSea Token: Release Date and How to Qualify for the Airdrop

OpenSea Token: Release Date and How to Qualify for the Airdrop

The NFT marketplace OpenSea, a pioneer in the space for the past seven years, is expected to launch its native token in 2025. A significant portion of the tokens will likely be distributed through a retroactive airdrop—a common way to reward the community for their past activity and support.

30 Dec 2024
5 Most Exciting Token Launches to Watch in 2025

5 Most Exciting Token Launches to Watch in 2025

In 2024, we saw a number of hot airdrops and token launches, from AI-powered projects to the rise of memecoins. Now, as we head into 2025, the crypto space is set to expand even further with an increasing number of cryptocurrencies.

27 Dec 2024

Latest News Alt

MORE
OKX Exchange: Avoid Common Mistakes When Trading Cryptocurrency

OKX Exchange: Avoid Common Mistakes When Trading Cryptocurrency

Practical Guide to Using the OKX Exchange OKX, formerly OKEx, started as a platform for cryptocurrency swaps. As it gained popularity, it expanded its services to become a full-scale exchange, supporting the buying and selling of a wide range of crypto assets. In January 2022, the platform rebranded, simplifying its name by removing the “Ex” […]

11 Jan 2025
Weekly Analysis of BTC, ETH, and the Stock Market (Jan 6, 2025)

Weekly Analysis of BTC, ETH, and the Stock Market (Jan 6, 2025)

An overview of BTC, ETH, XAUT, and S&P500 charts, along with the current cryptocurrency market dynamics.

06 Jan 2025
Weekly Analysis of BTC, ETH, and the Stock Market (Dec 30, 2024)

Weekly Analysis of BTC, ETH, and the Stock Market (Dec 30, 2024)

An overview of BTC, ETH, XAUT, and S&P500 charts, and the current cryptocurrency market dynamics.

30 Dec 2024

Might Be Interesting

MORE
Mining Farms Uncovered — How Crypto Is Mined at Scale

Mining Farms Uncovered — How Crypto Is Mined at Scale

As a cornerstone of the crypto industry, mining farms drive blockchain networks. But how do they work? Uncover the mechanics behind these cutting-edge hubs and their role in the crypto landscape.

07 Jan 2025
William Quigley, WAX/Tether: Stablecoins’ Role in Global Payments

William Quigley, WAX/Tether: Stablecoins’ Role in Global Payments

William Quigley, co-founder of WAX and Tether, firmly believes that stablecoins are more than a tool for traders—they’re the key to transforming the global economy. Already central to crypto trading and cross-border payments, their future potential is even more exciting.

04 Jan 2025
Why Blockchain Is Different from Traditional Databases

Why Blockchain Is Different from Traditional Databases

In the world of business and finance, information is everything. Traditional databases have been reliable tools for decades, but blockchain presents a groundbreaking alternative. What sets it apart, and could it lead to a paradigm shift?

03 Jan 2025
How Does Multisig Works and Protect Your Assets?

How Does Multisig Works and Protect Your Assets?

As threats to digital assets evolve, multisig technology provides a highly effective security layer. By requiring multiple signatures for transactions, it significantly reduces risks such as hacking and access loss.

02 Jan 2025
Crypto Price Gaps: Why Platforms Show Different Prices

Crypto Price Gaps: Why Platforms Show Different Prices

The crypto market has nuances you may not have noticed at first glance. For example, when you want to check the Bitcoin price, you probably Google it without thinking to compare the results. But when you monitor the market regularly and engage in trading, you notice the prices aren’t the same on all platforms.

24 Dec 2024
The Czech Republic and Its Crypto-Friendly Policies

The Czech Republic and Its Crypto-Friendly Policies

The Czech Republic is emerging as a crypto-friendly nation, recognizing cryptocurrencies as legitimate payment methods and encouraging their use in business. But its regulatory framework is still taking shape. Here’s how crypto is managed today.

23 Dec 2024

Opinions

8 Commandments for Crypto Exchange Users

8 Commandments for Crypto Exchange Users

While cryptocurrency exchanges offer many security features, they are still vulnerable to hacks, fraud, and other criminal activity. Remember, no online platform can guarantee 100% protection for your funds. Follow these eight key rules to reduce your risks. Rule #1: Don’t Believe in the Myth of Absolute Exchange Security Even the largest and most seemingly […]

12 Jan 2025
10 Key Investment Trends to Watch in 2025: Green Crypto, Regulations, and More

10 Key Investment Trends to Watch in 2025: Green Crypto, Regulations, and More

Donald Trump is back, Germany’s economy is in trouble, while U.S. economic indicators seem to have a robust momentum, and interest rates are sliding downhill. Sounds dramatic? It is. But 2025 isn’t all doom and gloom—it’s full of opportunities for investors who know where to look. Whether you’re a seasoned pro or someone still figuring […]

12 Jan 2025
MORE

Interviews

Dmytro Gordon and Volodymyr Nosov: A Sensational Interview

Dmytro Gordon and Volodymyr Nosov: A Sensational Interview

Volodymyr Nosov, CEO of Europe’s largest crypto exchange WhiteBIT, sat down with Dmytro Gordon, one of Ukraine’s most prominent journalists. The interview touched on Bitcoin, crypto, WhiteBIT, cars, keys to success, and business vision.

18 Dec 2024
WhiteBIT CEO: Standing Strong Against Russian Aggression

WhiteBIT CEO: Standing Strong Against Russian Aggression

In an interview with BTC-ECHO, Volodymyr Nosov, the founder and CEO of WhiteBIT, discussed the impact of Russian aggression on the crypto exchange’s business, how WhiteBIT stays a top competitor in the industry, and when he believes our financial system will be completely transformed.

04 Oct 2024
MORE