{"id":13486,"date":"2022-08-10T09:54:54","date_gmt":"2022-08-10T09:54:54","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/web3-wallet-provider-slope-linked-to-solana-attack\/"},"modified":"2022-08-10T09:54:54","modified_gmt":"2022-08-10T09:54:54","slug":"web3-wallet-provider-slope-linked-to-solana-attack","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/web3-wallet-provider-slope-linked-to-solana-attack\/","title":{"rendered":"Web3 wallet provider Slope linked to Solana attack"},"content":{"rendered":"<p><b>(Originally posted on : CoinJournal: Latest Bitcoin, Ethereum &amp; Crypto News )<\/b><br \/>\n<\/p>\n<div>\n<p>After the Solana attack that started on August 2, details have emerged linking a third-party Web3 wallet provider Slope to the attack.<\/p>\n<p>More than 8,000 Solana hot wallets were attacked and approximately $8 million worth of crypto assets were stolen. At the onset of the attack, Solana advised its users to switch to hardware wallets although it was too late since users had already lost funds.<\/p>\n<p>Today, Solana has updated its community via <a href=\"https:\/\/twitter.com\/SolanaStatus\/status\/1554921396408647680?s=20&amp;t=4A4qJo_p_cVu7Pb8NEqVzQ\">Twitter<\/a> after discovering that the affected addresses were part of Slope Wallet, which is a Web3 wallet.<\/p>\n<p>The tweet by Solana stated:<\/p>\n<p><em>\u201cAfter an investigation by developers, ecosystem teams, and security auditors, it appears affected addresses were at one point created, imported, or used in Slope mobile wallet applications.\u201d<\/em><\/p>\n<p>slope has a web-based crypto wallet, a mobile app, and a browser extension. It is integrated with Solana Pay and it allows users to send and receive tokens on the Solana network.<\/p>\n<h2>What we know about the Solana attack so far<\/h2>\n<p>Solana has stated that the details of what really transpired are still unclear although there is evidence that \u201cSlope wallet was logging or transmitting user mnemonics and private keys.\u201d\u00a0<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">While not certain that this is the exploit, it appears to now be confirmed that Slope wallet was logging or transmitting user mnemonics and private keys. See screenshot in this tweet showing private key and mnemonic in what appears to be a network request <a href=\"https:\/\/t.co\/oBkfrHP9I7\">https:\/\/t.co\/oBkfrHP9I7<\/a><\/p>\n<p>\u2014 Laine \u2764\ufe0f stakewiz.com (@laine_sa_) <a href=\"https:\/\/twitter.com\/laine_sa_\/status\/1554931383528632320?ref_src=twsrc%5Etfw\">August 3, 2022<\/a><\/p>\n<\/blockquote>\n<p>Nevertheless, Solana has said that there is no evidence that the Solana Protocol or its cryptography was compromised during the attack.<\/p>\n<p>After the revelation of Slope\u2019s link to the attack, Solana co-founder, Anatoly Yakovenko tweeted advising Slope users to generate their seed phrase in a different wallet as soon as possible. Binance CEO, Changpeng Zhao, echoed Anatoly\u2019s advice adding that users could use Binance.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">If you used a Slope wallet (for SOL) in the past, move your funds to a different wallet ASAP. Do not &#8220;import&#8221; the old wallet. Use a new private key or seed phrase. If you don&#8217;t know those words mean, send your SOL to <a href=\"https:\/\/twitter.com\/binance?ref_src=twsrc%5Etfw\">@binance<\/a>. The easy way. <a href=\"https:\/\/t.co\/t1lYcgaX5z\">https:\/\/t.co\/t1lYcgaX5z<\/a><\/p>\n<p>\u2014 CZ \ud83d\udd36 Binance (@cz_binance) <a href=\"https:\/\/twitter.com\/cz_binance\/status\/1554922295428358146?ref_src=twsrc%5Etfw\">August 3, 2022<\/a><\/p>\n<\/blockquote>\n<p>On its part, Slope issued a <a href=\"https:\/\/docs.google.com\/document\/d\/1zdm2KMW2g6JYHsdmSe8zDs56l4NfL-MaQ7nIbV9ohc8\/edit\">letter\u00a0<\/a>explaining to its customers the hypothesis of the attack and stating that it could not confirm anything yet. In the letter, Slope notes:<\/p>\n<p><em>\u201cWe feel the community\u2019s pain, and we were not immune. Many of our own staff and founders\u2019 wallets were drained.\u201d<\/em><\/p>\n<p>Details of what really happened are still trickling in as Solana and Slope Wallet users are advised to take caution.<\/p>\n<p>The price of SOL, the native token of the Solana network has taken a hit and has dipped by over 10% over the last two days. At the time of writing, Solana was trading at $38.86.<\/p>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><a href=\"https:\/\/coinjournal.net\/news\/web3-wallet-provider-slope-linked-to-yesterdays-solana-attack\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : CoinJournal: Latest Bitcoin, Ethereum &amp; Crypto News ) After the Solana attack that started on August 2, details have emerged linking a third-party Web3 wallet provider Slope to the attack. More than 8,000 Solana hot wallets were attacked and approximately $8 million worth of crypto assets were stolen. At the onset [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":13487,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[35],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/13486"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=13486"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/13486\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/13487"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=13486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=13486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=13486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}