Solana Network Suffers Multi-Million Dollar Hack, Leaving Wallets Drained
The Solana network suffered a multi-million dollar attack on Wednesday, as horrified users came to the realization that their wallets are now empty from all their funds.
The hacker successfully drained around $6 million from user wallets. The exact details of the attack remain unknown, however, the Solana team is investigating the matter.
A spokesperson for Solana Labs said that ongoing investigations into the breach currently indicate that there is “no evidence” that Solana’s network is at fault for the exploit.
“Engineers from multiple ecosystems, with the help of several security firms, are investigating drained wallets on Solana. There is no evidence hardware wallets are impacted,” Austin Federa, a spokesman for the project, said in a statement.
In a tweet, he noted: “Much remains unknown at this point – except that hardware wallets are not impacted. There’s also widespread reports of ETH wallets being compromised, but it’s not clear if that is related or a separate issue.”
An attacker appears to be draining SOL and SPL tokens in an apparent exploit on the Solana network.
Solana auditor OtterSec tweeted this evening that more than 5000 Solana wallets have been drained in the past few hours, corroborating numerous reports from people on Twitter claiming their balances have disappeared. OtterSec’s analysis showed the transactions were signed by the owners, which the auditor said suggested a private key compromise. The exploit may also affect ETH users.
Wallets that have been inactive for more than six months appear to be those hardest hit, according to The Block. Users of Phantom and Slope wallets say they have lost funds.
“We are working closely with other teams to get to the bottom of a reported vulnerability in the Solana ecosystem,” tweeted Phantom. “At this time, the team does not believe this is a Phantom-specific issue.”
At time of publication, it is unclear where the exploit originated. Non-fungible token marketplace Magic Eden recommended users to revoke permissions for any suspicious links within Phantom wallets in a tweet to users.
Gaming firm Star Atlas issued a community warning to users, saying a large scale exploit of Solana is in progress and advising users to revoke permissions for all apps in their wallets and move funds to cold storage.