SlowMist: Beware of Solana Wallet Owner Authority Tampering Attack
BlockBeats News, December 3rd. SlowMist Security Team released a security advisory regarding a recent phishing attack incident. A user fell victim to a phishing attack, resulting in the transfer of the account's Owner permission. The user attempted to revoke the authorization but was unable to do so. The user's assets worth over $3 million were stolen, with an additional $2 million worth of assets stored in a DeFi protocol that could not be transferred (currently, this part of the assets worth around $2 million has been successfully rescued with the assistance of the related DeFi protocol). This attack was not the traditional "authorization theft" but rather a replacement of the core permission (Owner permission) by the attacker, rendering the victim unable to transfer funds, revoke authorization, or operate DeFi assets despite the funds "appearing normal" but being beyond their control.
The attacker exploited two counterintuitive scenarios to successfully deceive the user into clicking:
1. Usually, when signing a transaction, the wallet would simulate the execution result of the transaction. If there were any fund changes, it would be displayed on the user interface. However, the attacker's carefully crafted transaction showed no fund changes;
2. In the traditional Ethereum EOA account, the ownership is controlled by the private key. Users subjectively were unaware that Solana has a feature that can modify account ownership.
SlowMist reminds users to be vigilant when authorizing signatures and to confirm whether there are hidden operations such as modifying high-risk permissions like Owner in them.
You may also like

Wall Street's Most Mysterious Money-Making Machine, Crashing Bitcoin Price at 10 a.m. Sharp Every Day

Key Market Information Discrepancy on February 26th - A Must-Read! | Alpha Morning Report

How was the Backpack staking token swap established?

Can You Still Launch a VC Firm Today?

Claude Cowork Adds Scheduled Task, Jane Street Incident Continues to Stir, What's the Overseas Crypto Community Talking About Today?

Leveraging $6,000 to Move a $200M Market Cap? How Polymarket Creates an "Insider Trading Illusion"
$8B Traded in 15 Days: How WEEX AI Trading Hackathon Tested Real-Market AI Strategies
How profitable is AI trading in real crypto markets? WEEX's $1.88M global AI hackathon reveals $8B volume, 227% ROI, API strategy data, and why only 8 of 37 traders made profit.

Advantages and Challenges of Modern Cryptocurrency Trading Platforms
Key Takeaways: Modern cryptocurrency trading platforms offer enhanced security measures to protect user assets. User-friendly interfaces and comprehensive…

Original Article Unavailable: Bridging Cryptocurrencies and the Emerging Trends
Key Takeaways Cryptocurrency markets are increasingly woven into the fabric of global financial systems. With advancements in blockchain…

Untitled
I’m sorry, but I am unable to fulfill this request as it lacks specific content from the original…

The one who bought the Meta stablecoin Diem back in the day is a good friend of SBF.

February 25th Market Key Insights, How Much Did You Miss Out?

Dragonfly Partner Haseeb Conversation: The AI Apocalypse is Far Away; Smart Contracts are Machine-Destined Law

IOSG: DeFi Upward, User Downward; Curator's New Paradigm of CeDeFi

DDC continues to advance its Bitcoin reserve strategy, with a total holding of 2118 BTC

From Mining Enterprise to Infrastructure Builder, Bitdeer Unpacks the Survival Logic behind BTC

How Can Agentic Commerce Empower AI to Start Making Money?
