News

Solana Is Widely Attacked Due To The Disclosure Of Slope Wallet’s Private Key

Slope Finance appears to be the source of the Solana mining that has affected thousands of users. Wallet owners are advised to transfer funds immediately from Slope imported wallets.

Solana crashed due to Slope wallet

As was updated in an earlier Coincu News article, on August 3, Solana experienced a security attack that affected over 8000 wallets of the platform and the damage is estimated at around $580 million.

Finally, details about the genesis of the exploit are becoming public. Wednesday night, Slope released a statement recommending all wallet owners to transfer any cash in wallets imported into Slope. The warning expanded on the advice to state that it does “not recommend using the same seed phrase on this new wallet that you had on Slope.”

Fantom wallet hinted at by the platform as the source of the incident has also been confirmed “complications related to importing accounts to and from Slope Finance“.

In the Twitter thread, the Solana Foundation revealed that “private key information was inadvertently transmitted to an application monitoring service“.

What’s remarkable in a tragic story is that the problem doesn’t appear to be a blockchain or seeding issue. A flaw in the cryptographic proofs of the Solana blockchain could have a devastating impact on the entire cryptocurrency ecosystem. However, this appears to be no longer on the tokens, and the Solana Foundation asserts that “there is no evidence that the Solana protocol or its cryptography has been compromised.”

In a log screenshot from Moon Rank NFT, Foobar highlighted the possibility of including private keys and memorable phrases in the Slope API call. While the POST request appears to have been sent over SSL encryption, the fact that a root phrase is included is a cause for concern. One possible cause is a man-in-the-middle attack, where a malicious actor can overhear communications between two parties to steal sensitive information.

Binance founder and CEO, CZ, has also now recommended all users who have used wallets on Slope Finance move funds to a fresh wallet or to Binance if you do not understand the words “private key or seed phrase.”

Fortunately, the total stolen assets included an illiquid Shitcoinsworth $570 million on Solscan. Therefore, the actual amount of money that was temporarily stolen was less than $10 million.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join CoinCu Telegram to keep track of news: https://t.me/coincunews

Follow CoinCu Youtube Channel | Follow CoinCu Facebook page

Foxy

CoinCu News

Victor

Recent Posts

Bonk’s ICO Was Just the Start: Why BTFD Coin’s Stage 7 Price Rollback Is Your Second Shot at Crypto Glory

BTFD Coin is offering a chance to relive the glory days of meme coin investing,…

4 minutes ago

Decoding BDAG’s AMA: A Blueprint for Scalable Blockchain and Enhanced Community Ties

Explore key takeaways from BlockDAG’s AMA, showcasing strides in scalability, growth of the ecosystem, and…

19 minutes ago

Best Cryptos with 1000X Potential: Qubetics Revolutionises Blockchain as Polkadot and Cosmos Shape the Future

Discover why Qubetics, Polkadot, and Cosmos are the best cryptos with 1000X potential, offering innovation,…

4 hours ago

Best Coins to Buy in December 2024: Qubetics Offer 630% ROI, Polkadot Delivers on Interoperability and Near Protocol’s Scalability is Talk of the Town

Explore the best coins to buy in December 2024—Qubetics with its thrilling presale, Polkadot’s interoperability,…

10 hours ago

Crypto Market Outlook 2025 Key Factors to Watch

The Crypto Market Outlook 2025 highlights key areas: stablecoin growth, tokenization, crypto ETFs, DeFi innovation,…

13 hours ago

Bitcoin Quantum Computing Threat Expected to Take Decades

The Bitcoin quantum computing threat is years away, but reserves already support post-quantum signatures via…

13 hours ago

This website uses cookies.