Incident: Crypto Hack on Solana Network: $6m Drained from 8,000 Wallets

Published Date: 2022-08-03

Postmortem Analysis
Timeline 1. The software failure incident targeting the Solana crypto network and resulting in nearly $6m being drained from accounts happened on August 2, 2022, as reported in Article [131277].
System 1. Wallet software used by certain wallets [131277] 2. Solana crypto network [131277]
Responsible Organization 1. A "malicious actor" targeted wallets linked to the Solana crypto network, leading to the draining of funds from approximately 8,000 wallets [131277]. 2. The attack on the Solana network was attributed to a single hacker, as mentioned by Elliptic, a blockchain consultancy [131277].
Impacted Organization 1. Users of the Solana blockchain, with approximately 8,000 wallets affected, including the Solana cryptocurrency and non-fungible tokens [131277].
Software Causes 1. The software cause of the failure incident was a flaw in certain wallet software rather than in the Solana blockchain itself, as identified by Elliptic [131277].
Non-software Causes 1. The hacker targeting 8,000 wallets linked to the Solana crypto network [131277]. 2. The exploit affecting approximately 8,000 wallets where users store their cryptocurrency and private keys [131277]. 3. The attack resulting in the draining of funds from the wallets, including Solana cryptocurrency, non-fungible tokens, and over 300 Solana-based tokens [131277]. 4. The flaw in certain wallet software being identified as a contributing factor to the incident, rather than a fault in the Solana blockchain itself [131277].
Impacts 1. Nearly $6 million was drained from accounts linked to the Solana crypto network due to a hacker targeting 8,000 wallets [131277]. 2. The attack resulted in funds being taken from approximately 8,000 wallets on the Solana network [131277]. 3. The stolen assets included the Solana cryptocurrency (SOL), non-fungible tokens (NFTs), and over 300 Solana-based tokens [131277]. 4. The incident highlighted a flaw in certain wallet software rather than in the Solana blockchain itself [131277].
Preventions 1. Implementing thorough security audits and code reviews of the wallet software to identify and fix any vulnerabilities [131277]. 2. Regularly updating and patching the wallet software to address any known security issues [131277]. 3. Providing security training and awareness programs for users to prevent falling victim to phishing attacks or other social engineering tactics [131277].
Fixes 1. Identifying and fixing the root cause of the exploit in the wallet software used by certain wallets linked to Solana could help prevent similar incidents in the future [131277].
References 1. Solana Foundation 2. Elliptic

Software Taxonomy of Faults

Category Option Rationale
Recurring multiple_organization (a) The software failure incident related to the hack on the Solana crypto network is specific to the Solana Foundation. There is no mention in the provided article of a similar incident happening before within the same organization. (b) The article mentions that users of the Solana blockchain have become the latest target for crypto hackers, indicating that similar incidents have occurred with other organizations or blockchain networks in the past. However, there is no specific mention of a similar incident happening again at other organizations in the provided article.
Phase (Design/Operation) design, operation (a) The software failure incident related to the design phase is indicated in the article. The incident on the Solana crypto network, where nearly $6m was drained from accounts due to a hacker targeting 8,000 wallets, was attributed to a flaw in certain wallet software rather than the Solana blockchain itself. Elliptic, a blockchain consultancy, mentioned that the root cause of the exploit was still unknown but appeared to be due to a flaw in certain wallet software [131277]. (b) The software failure incident related to the operation phase is evident in the article as well. The hack that affected approximately 8,000 wallets on the Solana network was a result of a malicious actor targeting wallets linked to Solana. This indicates a failure in the operation or misuse of the system, leading to the draining of funds from the wallets [131277].
Boundary (Internal/External) within_system (a) The software failure incident related to the drained funds from accounts linked to the Solana crypto network was primarily within the system. The incident was attributed to a flaw in certain wallet software rather than a fault in the Solana blockchain itself. Elliptic, a blockchain consultancy, mentioned that the root cause of the exploit appeared to be within the wallet software used by certain wallets [131277].
Nature (Human/Non-human) non-human_actions, human_actions (a) The software failure incident in the Solana crypto network was attributed to a flaw in certain wallet software rather than the blockchain itself. Elliptic, a blockchain consultancy, mentioned that the problem seemed to be with the software used by certain wallets, indicating a non-human action as the contributing factor to the failure [131277]. (b) The hack on the Solana crypto network, resulting in the draining of nearly $6 million from accounts linked to the network, was caused by a malicious actor targeting 8,000 wallets. This indicates that the failure was due to human actions, specifically the actions of the hacker who exploited the vulnerability in the wallet software to steal funds [131277].
Dimension (Hardware/Software) software (a) The software failure incident related to the Solana crypto network hack seems to be primarily attributed to software rather than hardware. The Solana Foundation mentioned that engineers are working with security researchers to identify the root cause of the exploit, which is currently unknown [131277]. Additionally, Elliptic, a blockchain consultancy, stated that the problem appeared to be with software used by certain wallets rather than the Solana blockchain itself [131277]. They highlighted that the root cause of the incident was not clear but seemed to be due to a flaw in certain wallet software, indicating a software-related failure.
Objective (Malicious/Non-malicious) malicious (a) The software failure incident in this case is malicious. The incident involved a hacker targeting 8,000 wallets linked to the Solana crypto network and draining nearly $6 million from these accounts. The Solana Foundation described the actor as "malicious" and mentioned that engineers are working with security researchers to identify the root cause of the exploit [131277]. Additionally, Elliptic, a blockchain consultancy, stated that users of the Solana blockchain were targeted by crypto hackers, with over $5.8 million drained from wallets. The attack was attributed to a flaw in certain wallet software rather than the Solana blockchain itself, indicating a deliberate attempt to exploit vulnerabilities in the software [131277].
Intent (Poor/Accidental Decisions) accidental_decisions (a) The intent of the software failure incident related to poor_decisions: - The software failure incident involving the hack on the Solana crypto network was not explicitly attributed to poor decisions in the articles provided [131277]. The root cause of the exploit was unknown at the time of reporting, and engineers were working to identify the source of the attack. It was mentioned that the problem seemed to be with the software used by certain wallets rather than the blockchain itself, indicating a potential flaw in the wallet software that was exploited by the hacker. (b) The intent of the software failure incident related to accidental_decisions: - The software failure incident involving the hack on the Solana crypto network could be attributed to accidental decisions or mistakes. Elliptic, a blockchain consultancy, mentioned that the root cause of the exploit was not clear but appeared to be due to a flaw in certain wallet software rather than the blockchain itself. This suggests that the incident may have been a result of unintended vulnerabilities in the wallet software that were exploited by the hacker [131277].
Capability (Incompetence/Accidental) development_incompetence, accidental (a) The software failure incident related to development incompetence is evident in the article as it mentions that the hack on the Solana crypto network resulted in nearly $6 million being drained from accounts linked to the network. The Solana Foundation stated that engineers are currently working with multiple security researchers and ecosystem teams to identify the root cause of the exploit, which is unknown at this time. This indicates that there may have been a lack of professional competence in the development or security measures of the software that allowed the malicious actor to target the wallets and steal funds [131277]. (b) The software failure incident related to accidental factors is highlighted in the article by Elliptic, a blockchain consultancy. Elliptic mentioned that the problem appeared to be with software used by certain wallets rather than the Solana blockchain itself. They stated that the root cause of the exploit was not clear but appeared to be due to a flaw in certain wallet software, indicating that the failure was accidental and not intentionally introduced by the blockchain itself [131277].
Duration temporary The software failure incident related to the Solana crypto network hack can be categorized as a temporary failure. The incident was described as a hack where a "malicious actor" targeted wallets linked to Solana, resulting in the draining of funds from approximately 8,000 wallets [131277]. The root cause of the exploit was initially unknown, and engineers were working with security researchers and ecosystem teams to identify it [131277]. Additionally, Elliptic, a blockchain consultancy, mentioned that the problem appeared to be with the software used by certain wallets rather than the Solana blockchain itself, indicating a specific software vulnerability [131277].
Behaviour omission, value, other (a) crash: The incident involving the Solana crypto network was not described as a crash where the system loses state and does not perform any of its intended functions [131277]. (b) omission: The software failure incident related to the Solana crypto network involved a hacker draining funds from wallets, indicating an omission in the system's intended function of securely storing cryptocurrency and private keys [131277]. (c) timing: The incident did not involve a timing failure where the system performs its intended functions correctly but too late or too early [131277]. (d) value: The software failure incident on the Solana network resulted in the system performing its intended functions incorrectly, leading to the theft of funds from wallets [131277]. (e) byzantine: The incident did not exhibit a byzantine behavior where the system behaves erroneously with inconsistent responses and interactions [131277]. (f) other: The software failure incident on the Solana network was attributed to a flaw in certain wallet software rather than the blockchain itself, indicating a specific type of software failure related to wallet software [131277].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence property, non-human (d) property: People's material goods, money, or data was impacted due to the software failure The software failure incident reported in Article #131277 resulted in nearly $6 million being drained from accounts linked to the Solana crypto network after a hacker targeted 8,000 wallets. The hack affected approximately 8,000 wallets where users store their cryptocurrency and private keys. The stolen assets included the Solana cryptocurrency, non-fungible tokens, and over 300 Solana-based tokens. The attack led to financial losses for the users whose wallets were compromised [131277].
Domain finance (a) The failed system was related to the finance industry as it involved the draining of funds from accounts linked to the Solana crypto network [131277].

Sources

Back to List