Cointime

Download App
iOS & Android

2022 Solana Exploits Overview: 11 Significant Attacks, $523 Million Lost

Validated Project

TL;DR

In 2022, Solana Blockchain has lost approximately $523 Million in stolen funds in exploits.

Introduction

Solana, a public blockchain platform, has suffered 11 significant attacks over the last year resulting in a total loss of ~$523 million. By far the largest incident was the exploit which occurred on the Wormhole Bridge resulting in the loss of $326 million, which is also the second largest exploit which has occurred exploit in terms of lost funds to have occurred this year. Of the 11 incidents, 10 lost over $1 million. You can see the breakdown of these exploits below.

 Image: Breakdown of funds lost by exploit. Source: CertiK

Exploits

Solana had seven major exploits this year including Wormhole, Cashio, Mango Market, Solend, and Optifi. These exploits led to a total profit loss of ~$492 million in user funds. The largest exploit on Solana protocol was the Wormhole incident, which led to a loss of ~$326 million. Attackers exploited a signature verification vulnerability in the Wormhole network to mint 120k Ether on Solana. The hack occurred due to a lack of signature verification authorizations, where the developers used a deprecated function to enable unverified forged signature passes. The second largest exploit on Solana occurred on October 11, 2022, when Mango Markets was exploited by a group of attackers that totaled a loss of $116 million. Attackers manipulated the value of a posted collateral to a higher price. Hackers then took out significant loans against the inflated collateral, which ended up draining Mango’s treasury.

Private Key Compromises

In 2022, $13.5 million has been lost due to private key exploits on the Solana blockchain. The largest private key compromise occurred on 2nd August 2022 when Slope wallet users began to notice that their assets were being transferred out of their wallet. It later became apparent that the private keys of Slope users were stored in plaintext on a third part server which was compromised. This meant that hackers were able to drain approximately 8,000 wallets which led to ~$8 million in losses. The second private key compromise occurred on On 16 December 2022, due to a Trojan virus compromising a key wallet on Raydium Protocol. The exploiter drained multiple liquidity pools which led to approximately $5.5 million worth of assets being stolen.

Private key compromise events are particularly harmful especially when a project has a high degree of centralization. In the case of the Raydium incident, one wallet was able to withdraw liquidity from multiple pools which presents a centralization risk if said wallet is mishandled or compromised. Always check certik.com audits and understand the centralization risks of a project and see what measures the team have taken to mitigated these security issues.

Exit Scams

Users on the Solana blockchain fell victim to multiple exit scams, losing millions to scammers. In 2022, there were four significant exit scams on the Solana blockchain totalling ~$5.3 million of stolen user funds. These exit scams included COPE, Big Daddy Ape Club, Doodled Dragons, and SolFire Finance, with the largest exit scam being SolFire Finance at ~$4.1 million user funds stolen. The SolFire Finance project owner stole all user funds and moved them to the Ethereum via a cross-chain bridge. The project then deleted their GitHub account and Twitter accounts.

Doing your own due diligence on a project is extremely important to avoid being the victim of an exit scam. There are a number of resources you can utilize to help you DYOR. For example, CertiK offers industry leading KYC investigations which mean the team behind a project are thoroughly vetted by skilled investigators and analysts. CertiK have uncovered a KYC actor industry which aims to trick KYC services into passing illegitimate projects. Look for the CertiK KYC badge on certik.com to help you DYOR in investing in trustworthy projects.

Conclusion

This year has been a tough one for DeFi platforms, especially Solana. Projects on Solana suffered multiple costly exit scams and exploits which included key compromises and code vulnerabilities. 

Comments

All Comments

Recommended for you

  • Another Iranian Oil Tanker Returns to Iran After Breaking US Blockade

    On April 21, according to CCTV News, maritime intelligence company 'TankerTrackers' reported that a tanker belonging to the National Iranian Tanker Company returned to Iran after unloading approximately 2 million barrels of crude oil in Indonesia, crossing the relevant maritime blockade line. The tanker is currently en route to Iran's main oil export hub, Khark Island, and is expected to arrive on April 22 local time. It is reported that the tanker set sail from Iran in late March, heading towards the Riau Islands of Indonesia.

  • White House: US and Iran on the Verge of Reaching an Agreement

    On April 21, White House Press Secretary Kayleigh McEnany stated in an interview with Fox News on the evening of the 20th that the United States and Iran are on the "verge of reaching an agreement." McEnany remarked, "The US has never been closer to achieving a truly good deal." However, she did not disclose any information regarding the current status of the negotiations. McEnany noted that even if an agreement is not reached, President Trump has multiple options and is not afraid to utilize these measures. Previous actions have demonstrated that Trump is not just "bluffing."

  • Kelp DAO Attacker Transfers 30,800 ETH to Special Address

    On April 21, news emerged that, according to monitoring by PeckShield, the Kelp DAO attacker transferred 30,800 ETH to a special address starting with 0x00000, possibly indicating a destruction action.

  • Trump: 'Midnight Hammer' Completely Dismantled Iran's Nuclear Dust Base

    On April 21, U.S. President Trump stated that the 'Midnight Hammer' operation has completely destroyed the 'nuclear dust' base within Iran. As a result, the cleanup will be a long and arduous process. The fake news media, including CNN and other corrupt media networks and platforms, have failed to give our great pilots the credit they deserve, instead always attempting to belittle and undermine them. They are losers!!! (Dongxin News Agency)

  • BTC Drops Below $76,000

    Market data shows that BTC has dropped below $76,000, currently priced at $75,999.63, with a 24-hour increase of 1.68%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Japan Officially Allows Export of Lethal Weapons Through Cabinet Resolution

    On April 21, according to Kyodo News, the Japanese government officially revised the 'Three Principles on Transfer of Defense Equipment' and its operational guidelines during a cabinet meeting, which will, in principle, allow the export of lethal weapons. (Xinhua News Agency)

  • Trump Claims Iran Will Negotiate

    On April 21, during a phone interview with CNN, U.S. President Trump stated that Iran "will negotiate" and expressed confidence in potential talks set to take place in Pakistan. Trump remarked, "They will negotiate; if they don't, they will face unprecedented problems." He also expressed hope that both sides could reach a "fair agreement" and emphasized that Iran "will not have nuclear weapons." Additionally, he defended military actions against Iran by stating there was "no choice" and claimed that they would ultimately "wrap things up."

  • Amazon to Invest Additional $5 Billion in Anthropic

    On April 21, Amazon announced on Monday that it will invest an additional $5 billion in the artificial intelligence company Anthropic, bringing the total investment to as much as $20 billion. Anthropic develops the Claude chatbot and programming tools, and plans to invest over $100 billion in Amazon's cloud technology and chips over the next decade.

  • Three U.S. Carrier Strike Groups May Deploy Simultaneously in the Middle East

    On April 21, according to CCTV, the U.S. military is expected to deploy three carrier strike groups simultaneously in the Middle East in the coming days. Currently, the USS Lincoln strike group is stationed in the Gulf of Oman, near the Strait of Hormuz, participating in maritime blockade operations; the USS Ford strike group is located in the northern Red Sea; and the USS Bush strike group, which is taking a route around Africa, is heading north from the southeast of Africa and is expected to enter the Arabian Sea—this carrier may replace the USS Ford in its mission. In the short term, the U.S. military may have three aircraft carriers in the Middle East.

  • BTC Surpasses $76,000

    Market data shows that BTC has surpassed $76,000, currently priced at $76,039.83, with a 24-hour increase of 1.67%. The market is highly volatile, so please ensure proper risk management.