SlowMist: Beware of Solana Wallet Owner Authority Tampering Attack
BlockBeats News, December 3rd. SlowMist Security Team released a security advisory regarding a recent phishing attack incident. A user fell victim to a phishing attack, resulting in the transfer of the account's Owner permission. The user attempted to revoke the authorization but was unable to do so. The user's assets worth over $3 million were stolen, with an additional $2 million worth of assets stored in a DeFi protocol that could not be transferred (currently, this part of the assets worth around $2 million has been successfully rescued with the assistance of the related DeFi protocol). This attack was not the traditional "authorization theft" but rather a replacement of the core permission (Owner permission) by the attacker, rendering the victim unable to transfer funds, revoke authorization, or operate DeFi assets despite the funds "appearing normal" but being beyond their control.
The attacker exploited two counterintuitive scenarios to successfully deceive the user into clicking:
1. Usually, when signing a transaction, the wallet would simulate the execution result of the transaction. If there were any fund changes, it would be displayed on the user interface. However, the attacker's carefully crafted transaction showed no fund changes;
2. In the traditional Ethereum EOA account, the ownership is controlled by the private key. Users subjectively were unaware that Solana has a feature that can modify account ownership.
SlowMist reminds users to be vigilant when authorizing signatures and to confirm whether there are hidden operations such as modifying high-risk permissions like Owner in them.
You may also like

Key Market Information Discrepancy on February 27th - A Must-See! | Alpha Morning Report

The Circle Beautiful Money Report: Is the True Winner of Stablecoins Not the Issuer?

Opinion: Bitcoin's 10-point Plunge Wasn't All Jane Street's Fault

Milestone AI-driven Layoff, a 50% Reduction in Force, Resulting in Unquestionable Capital Market Approval

WEEX P2P upgrade: Ad posting now available for regular users
To further improve liquidity and user participation in the P2P market and create a more open and efficient trading environment, WEEX now allows regular users to post ads on P2P. This update allows non-merchant users to post ads, opening up greater participation in the P2P marketplace.

Dovey Wan: The Great Liquidity Schism, Bitcoin May Never Keep Up with ARKK

Market Key Insights for February 26th, How Much Did You Miss?

L1 Value Capture Shrinks Significantly, ETH, SOL, HYPE Struggle to Return to All-Time High

Exploring the ‘Super Cycle’ in Artificial Intelligence: Insights from Brad Gerstner
Key Takeaways The concept of a ‘super cycle’ in AI technology is gaining traction, spearheaded by industry experts.…

Children and Trump’s Investment Program: Billionaires’ Contributions to “Trump Accounts”
Key Takeaways: President Donald Trump has introduced the “Trump Accounts” program, massively funded by billionaires to provide financial…

Could Stablecoins Resolve U.S. Debt? Standard Chartered Predicts $1 Trillion in Treasury Demand
Key Takeaways Projected Growth: The stablecoin market could see its capitalization soar to $2 trillion by 2028, significantly…

Missouri Advances Bitcoin Reserve Bill to House Committee in Policy Push
Key Takeaways Missouri pushes HB 2080, aiming to establish a state-run Bitcoin Strategic Reserve Fund. The bill mandates…

Ethereum Faces $1,500 Downside as Vitalik Buterin Sells 9,000 ETH
Key Takeaways Vitalik Buterin’s recent sale of nearly 9,000 ETH has triggered concerns over Ethereum’s price stability, given…

Hong Kong to Connect New Digital Bond Platform With Regional Crypto Tokenization Hubs
Key Takeaways Hong Kong is pioneering the integration of its debt market with blockchain technology through a new…

Elon’s Grok AI Predicts the Price of XRP, Cardano, and Ethereum by 2026
Key Takeaways Grok AI forecasts significant price growth for XRP, Cardano, and Ethereum by 2026. XRP could see…

Anchorage Digital Confirms Its Stake in Strategy’s STRC – A Sign of Long-term Confidence
Key Takeaways Anchorage Digital has officially disclosed holding Strategy’s STRC perpetual preferred stock, reinforcing its strategic alignment within…

Bitcoin Price Prediction: Major Miner Expands in Texas: Is a Massive BTC Production Surge Anticipating?
Key Takeaways: Canaan Inc. has expanded its role from hardware selling to direct Bitcoin production by acquiring a…

Crypto Price Prediction Today 25 February: XRP, Solana, Bitcoin
Key Takeaways Bitcoin’s recent surge to $66,000 reflects a potential bullish trend bolstered by institutional interest and regulatory…
Key Market Information Discrepancy on February 27th - A Must-See! | Alpha Morning Report
The Circle Beautiful Money Report: Is the True Winner of Stablecoins Not the Issuer?
Opinion: Bitcoin's 10-point Plunge Wasn't All Jane Street's Fault
Milestone AI-driven Layoff, a 50% Reduction in Force, Resulting in Unquestionable Capital Market Approval
WEEX P2P upgrade: Ad posting now available for regular users
To further improve liquidity and user participation in the P2P market and create a more open and efficient trading environment, WEEX now allows regular users to post ads on P2P. This update allows non-merchant users to post ads, opening up greater participation in the P2P marketplace.