{"id":14741,"date":"2021-12-05T04:59:56","date_gmt":"2021-12-05T03:59:56","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=14741"},"modified":"2021-12-05T05:00:07","modified_gmt":"2021-12-05T04:00:07","slug":"solana-corrects-bug-could-see-hackers-steal-funds","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/solana-corrects-bug-could-see-hackers-steal-funds\/","title":{"rendered":"Solana corrects a bug that could see hackers steal funds from Solana projects"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">Solana has corrected a problem that could have allowed hackers to steal $ 27 million in an hour<\/h5>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/11\/solana-sol-crypto.jpg\" alt=\"Solana corrects a bug that could see hackers steal funds from Solana projects\" class=\"wp-image-13397\" width=\"1200\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/11\/solana-sol-crypto.jpg 640w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/11\/solana-sol-crypto-300x225.jpg 300w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><figcaption>Solana corrects a bug that could see hackers steal funds from Solana projects<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Flaw in the Solana Protocol Library could allow hackers to steal<\/h2>\n\n\n\n<p>In the cryptocurrency industry, rug pulling and network exploits have dominated public opinion.<a href=\"https:\/\/coinscreed.com\/staging\/bitcoiner-loses-900-btc-in-a-defi-attack.html\" data-type=\"post\" data-id=\"14566\"> DeFi <\/a>applications have now lost over $2 billion to such hacks, including more than $120 million this week alone.<\/p>\n\n\n\n<p>Additionally, according to security researchers at Neodyme, if a bug is recently patched, there is a risk of thousands of dollars being stolen from the Solana ecosystem.<\/p>\n\n\n\n<p>Several articles Researchers revealed in a blog <a href=\"https:\/\/blog.neodyme.io\/posts\/lending_disclosure\" target=\"_blank\" rel=\"noopener\">post<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> that a flaw in the Solana Protocol Library (SPL (Reference Set for Solana Projects) could allow hackers to quickly steal funds from multiple Solana projects at an hourly rate of $27 million. The risk is estimated to be worth up to $2.6 billion in total.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/coinscreed.com\/staging\/el-salvadors-bitcoin-adoption-could-paraguay-be-next-in-line-to-make-bitcoin-a-legal-tender.html\" data-type=\"post\" data-id=\"10228\">Tulip<\/a> Protocol's return aggregator, as well as the Solend, Soda, and Larix credit protocols, all of which have a Total Value Locked (TVL) in the millions, could all be affected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How it all started<\/h2>\n\n\n\n<p>It all began in June when researcher Simon discovered the bug and reported it to Github. The error went unnoticed at this point because it did not pose an imminent risk. However, it remained unresolved or corrected, however, when it was reviewed on December 1.<\/p>\n\n\n\n<p>The researchers then began testing the exploit for vulnerabilities and evaluating the potential harm it could cause. Although the researcher initially dismissed it as a &#8220;seemingly harmless rounding error,&#8221; he later realized that large sums of money could be stolen through an infinite number of small transactions.<\/p>\n\n\n\n<p>This is because applications on Solana that use SPL reference the nearest integer when paying out, which results in the user receiving very little or even losing money if the user owes a fraction of the smallest reference unit of money. While this may appear insignificant, the total is incalculable if a single company takes advantage of this and adheres to it.<\/p>\n\n\n\n<p>The researchers estimate that they can make this error 150\u2013200 times in a single transaction and pack those many transactions into a single block following the test. They calculated that an exploit of this vulnerability could steal $7,500 per second, or $27 million per hour.<\/p>\n\n\n\n<p>Neodyme confirmed the existence of this bug by contacting several Solana projects that may have been impacted. Due to the fact that the majority of them are proprietary, the mission uncovered some roadblocks. <\/p>\n\n\n\n<p>Nonetheless, they made an attempt to contact several prominent projects to correct the errors, and Solana Labs also corrected the references to ensure that subsequent new projects were error-free.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solana has corrected a problem that could have allowed hackers to steal $ 27 million in an hour Flaw in the Solana Protocol Library could allow hackers to steal In the cryptocurrency industry, rug pulling and network exploits have dominated public opinion. DeFi applications have now lost over $2 billion to such hacks, including more [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":13397,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[81],"tags":[5814,5675],"class_list":["post-14741","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-altcoin-news","tag-bug-2","tag-solana-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/11\/solana-sol-crypto.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/14741","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=14741"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/14741\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/13397"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=14741"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=14741"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=14741"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}