SlowMist: Beware of Solana Wallet Owner Authority Tampering Attack
BlockBeats News, December 3rd. SlowMist Security Team released a security advisory regarding a recent phishing attack incident. A user fell victim to a phishing attack, resulting in the transfer of the account's Owner permission. The user attempted to revoke the authorization but was unable to do so. The user's assets worth over $3 million were stolen, with an additional $2 million worth of assets stored in a DeFi protocol that could not be transferred (currently, this part of the assets worth around $2 million has been successfully rescued with the assistance of the related DeFi protocol). This attack was not the traditional "authorization theft" but rather a replacement of the core permission (Owner permission) by the attacker, rendering the victim unable to transfer funds, revoke authorization, or operate DeFi assets despite the funds "appearing normal" but being beyond their control.
The attacker exploited two counterintuitive scenarios to successfully deceive the user into clicking:
1. Usually, when signing a transaction, the wallet would simulate the execution result of the transaction. If there were any fund changes, it would be displayed on the user interface. However, the attacker's carefully crafted transaction showed no fund changes;
2. In the traditional Ethereum EOA account, the ownership is controlled by the private key. Users subjectively were unaware that Solana has a feature that can modify account ownership.
SlowMist reminds users to be vigilant when authorizing signatures and to confirm whether there are hidden operations such as modifying high-risk permissions like Owner in them.
You may also like

Flow Chain Rollback Sparks Outrage, Whale Starts Lighter Rebalancing, Mainstream Ecosystem Update Overview

ETHPanda Talk | From Nethermind to Ethereum Foundation: Tomasz's Ethereum Core Development Journey

2025 Cryptocurrency Memes News Released

Lido DAO’s Increased Development and Market Dynamics Elevate LDO Price
Key Takeaways Lido DAO’s development activities have surged by 690%, signifying substantial growth. The Lido DAO token (LDO)…

Hyperliquid Whales Shift Strategies: BTC Longs Decline, ETH Shorts Dominate
Key Takeaways A significant reduction in Bitcoin long positions has been observed on Hyperliquid, with large holders decreasing…

December 26th Market Key Intelligence, How Much Did You Miss?

Crypto Christmas Heist: Over $6 Million Lost, Trust Wallet Chrome Extension Wallet Hacked Analysis

Trust Wallet Browser Extension Security Incident Leads to Losses
Key Takeaways Trust Wallet identified a significant security breach in its browser extension version 2.68. Approximately over $6…

Ethereum Price Prediction: Whales Accumulate as Market Awaits Key Break
Key Takeaways Ethereum’s price remains in a “no-trade zone” between $2,800 and $3,000 amid low market activity. Whale…

Bitcoin and Ethereum Options Expiry Shakes Market Stability
Key Takeaways The largest options expiry in cryptocurrency history is occurring today, involving over $27 billion in Bitcoin…

Trust Wallet Hack Results in $3.5 Million Loss for Major Wallet Holder
Key Takeaways A significant Trust Wallet hack led to the theft of $3.5 million from an inactive wallet.…

PancakeSwap Launches LP Rewards on Base Network
Key Takeaways PancakeSwap has introduced liquidity provider (LP) rewards for 12 v3 pools on the Base network, facilitated…

Ethereum in 2026: Glamsterdam and Hegota Forks, Layer 1 Scaling, and More
Key Takeaways Ethereum is poised for crucial developments in 2026, particularly with the Glamsterdam and Hegota forks. Glamsterdam…

Social Engineering in the Crypto Universe: Safeguarding Your Assets in 2025
Key Takeaways Social engineering, a psychological manipulation tactic, has been the leading cause of crypto asset theft in…

Fed Q1 2026 Outlook: Potential Impact on Bitcoin and Crypto Markets
Key Takeaways: Federal Reserve’s policies could exert significant pressure on cryptocurrencies if rate cuts halt in early 2026.…

Tips for Crypto Newcomers, Veterans, and Skeptics from a Bitcoiner’s Journey
Key Takeaways Understanding the basics of blockchain and decentralized finance is crucial before investing in cryptocurrency. Newcomers should…

Trust Wallet to Reimburse $7 Million Lost in Christmas Hack: An Inside Job?
Key Takeaways Trust Wallet’s browser extension was compromised, leading to a $7 million loss on Christmas Day. The…

Ethereum Price: New Highs in 2026 Unlikely According to Crypto Analyst Ben Cowen
Key Takeaways Analyst Ben Cowen suggests Ethereum may not reach new highs in 2026 due to prevailing market…
Flow Chain Rollback Sparks Outrage, Whale Starts Lighter Rebalancing, Mainstream Ecosystem Update Overview
ETHPanda Talk | From Nethermind to Ethereum Foundation: Tomasz's Ethereum Core Development Journey
2025 Cryptocurrency Memes News Released
Lido DAO’s Increased Development and Market Dynamics Elevate LDO Price
Key Takeaways Lido DAO’s development activities have surged by 690%, signifying substantial growth. The Lido DAO token (LDO)…
Hyperliquid Whales Shift Strategies: BTC Longs Decline, ETH Shorts Dominate
Key Takeaways A significant reduction in Bitcoin long positions has been observed on Hyperliquid, with large holders decreasing…
December 26th Market Key Intelligence, How Much Did You Miss?
Popular coins
Latest Crypto News
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Services:support@weex.com