SlowMist: Beware of Solana Wallet Owner Authority Tampering Attack
BlockBeats News, December 3rd. SlowMist Security Team released a security advisory regarding a recent phishing attack incident. A user fell victim to a phishing attack, resulting in the transfer of the account's Owner permission. The user attempted to revoke the authorization but was unable to do so. The user's assets worth over $3 million were stolen, with an additional $2 million worth of assets stored in a DeFi protocol that could not be transferred (currently, this part of the assets worth around $2 million has been successfully rescued with the assistance of the related DeFi protocol). This attack was not the traditional "authorization theft" but rather a replacement of the core permission (Owner permission) by the attacker, rendering the victim unable to transfer funds, revoke authorization, or operate DeFi assets despite the funds "appearing normal" but being beyond their control.
The attacker exploited two counterintuitive scenarios to successfully deceive the user into clicking:
1. Usually, when signing a transaction, the wallet would simulate the execution result of the transaction. If there were any fund changes, it would be displayed on the user interface. However, the attacker's carefully crafted transaction showed no fund changes;
2. In the traditional Ethereum EOA account, the ownership is controlled by the private key. Users subjectively were unaware that Solana has a feature that can modify account ownership.
SlowMist reminds users to be vigilant when authorizing signatures and to confirm whether there are hidden operations such as modifying high-risk permissions like Owner in them.
You may also like

From Stanford Lab to Silicon Valley Streets: How OpenMind is Solving the "Last Mile" Problem of the Machine Economy?

PlanX: Reconstructing On-Chain Execution with AI, Moving Towards a New Paradigm

US Judge Allows Binance Unregistered Token Lawsuit to Advance
Key Takeaways: A federal judge in Manhattan dismissed Binance’s petition to resolve a securities lawsuit through private arbitration,…

Crypto VC Paradigm Plans $1.5 Billion Expansion into AI and Robotics
Key Takeaways: Paradigm is setting up a new $1.5 billion fund to explore AI, robotics, and other emerging…

Ethereum Smart Accounts Set to Launch Within a Year, According to Vitalik Buterin
Key Takeaways: Ethereum’s “account abstraction” or smart accounts might be introduced in the coming year through the Hegota…

Bitcoin Recovers After Iran Conflict Shocks Market, Reverses $5K Fall in Just 24 Hours
Key Takeaways: Bitcoin dropped to approximately $63,000 amid tensions but rebounded to $68,200 within a day. Volatility led…

Former Mt. Gox CEO Suggests Hardfork to Retrieve $5.2 Billion in Bitcoin
Key Takeaways: Mark Karpelès, former CEO of Mt. Gox, proposes a Bitcoin network hard fork to access nearly…

South Korea National Tax Service’s Mistake Resulted in $4.8 Million Crypto Loss
Key Takeaways South Korea’s National Tax Service inadvertently exposed private keys, resulting in a $4.8 million crypto loss.…

Morgan Stanley Seeks National Trust Charter for Cryptocurrency Custody
Key Takeaways: Morgan Stanley has initiated a significant step toward digital asset management by applying for a national…

Solana Price Outlook: Major ETF Inflows Hint at Institutional Moves
Key Takeaways: Solana has experienced substantial ETF inflows, prompting speculation about institutional buy-in. On February 25, Solana recorded…

Bitcoin Price Prediction: Wikipedia Founder Warns BTC Could Plunge Below $10K — Should Investors Worry?
Key Takeaways Wikipedia co-founder Jimmy Wales warns Bitcoin might decline to below $10,000, prompting a bearish outlook. Wales…

China’s DeepSeek AI Foresees a Bright Future for XRP, Bitcoin, and Ethereum
Key Takeaways: DeepSeek AI predicts that XRP, Bitcoin, and Ethereum may reach new all-time highs within the next…

Can BTC, ETH, and SOL Liquidity Collaborate Effectively? Exploring LiquidChain’s Staking and Settlement Approach
Key Takeaways LiquidChain introduces a novel Layer 3 framework aimed at integrating liquidity across Bitcoin, Ethereum, and Solana.…

Canton Crypto Network vs. XRP: Exploring DTCC’s Infrastructure and Liquidity Dynamics
Key Takeaways Canton Network is crafted for institutional finance, emphasizing privacy and regulatory alignment, critical for the onchain…

Axiom Crypto Exposed: Alleged $400k Insider Trading Scandal Revealed
Key Takeaways A whistleblower has brought to light an alleged insider trading scheme at Axiom Crypto, revealing governance…

Ethereum $159B Stablecoin Dominance: Why Infrastructure Triumphs Over Price
Ethereum’s role as a settlement layer has seen it capture over 53%, or $159 billion, of the $300…

Crypto Price Forecast Today: February 26 – XRP, Solana, Dogecoin
Key Takeaways Potential impact of U.S. regulatory clarity: Up-and-coming regulations like the CLARITY Act in the U.S. are…

XRP Price Outlook: Recent Bug Expose and Protection – What’s Next for XRP Holders?
Key Takeaways A significant flaw in the XRP Ledger was found but addressed before it posed any real…
From Stanford Lab to Silicon Valley Streets: How OpenMind is Solving the "Last Mile" Problem of the Machine Economy?
PlanX: Reconstructing On-Chain Execution with AI, Moving Towards a New Paradigm
US Judge Allows Binance Unregistered Token Lawsuit to Advance
Key Takeaways: A federal judge in Manhattan dismissed Binance’s petition to resolve a securities lawsuit through private arbitration,…
Crypto VC Paradigm Plans $1.5 Billion Expansion into AI and Robotics
Key Takeaways: Paradigm is setting up a new $1.5 billion fund to explore AI, robotics, and other emerging…
Ethereum Smart Accounts Set to Launch Within a Year, According to Vitalik Buterin
Key Takeaways: Ethereum’s “account abstraction” or smart accounts might be introduced in the coming year through the Hegota…
Bitcoin Recovers After Iran Conflict Shocks Market, Reverses $5K Fall in Just 24 Hours
Key Takeaways: Bitcoin dropped to approximately $63,000 amid tensions but rebounded to $68,200 within a day. Volatility led…