{"id":32785,"date":"2022-08-05T07:29:03","date_gmt":"2022-08-05T11:29:03","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=32785"},"modified":"2022-08-05T07:29:08","modified_gmt":"2022-08-05T11:29:08","slug":"experts-discover-private-keys-on-slope-servers-access-unclear","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/experts-discover-private-keys-on-slope-servers-access-unclear\/","title":{"rendered":"Experts discover private keys on Slope servers, access unclear"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-the-newest-steps-in-the-solana-exploit-investigation-are-being-unpacked-by-blockchain-analysis-companies-as-teams-work-to-determine-how-private-keys-were-taken\">The newest steps in the Solana exploit investigation are being unpacked by blockchain analysis companies as teams work to determine how private keys were taken.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-1024x576.jpg\" alt=\"Experts discover private keys on Slope servers, access unclear\" class=\"wp-image-32789\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-1536x864.jpg 1536w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340.jpg 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>Experts discover private keys on Slope servers, access unclear<\/figcaption><\/figure>\n\n\n\n<p>About 8,000 private keys used to deplete Solana-based wallets were obtained by<a href=\"https:\/\/coinscreed.com\/staging\/nomad-announces-10-bounty-to-hackers-following-recent-hack.html\" target=\"_blank\" rel=\"noreferrer noopener\"> hackers<\/a>, and blockchain auditing companies are still trying to determine how they did it.<\/p>\n\n\n\n<p>Investigations are still going on after thieves managed to take SOL and SPL tokens worth about $5 million on August 3. Participants in the ecosystem and security companies are helping to unravel the details of the incident.<\/p>\n\n\n\n<p>The two SOL wallet providers, Phantom and Slope.Finance, whose users' accounts were impacted by the attacks, has collaborated extensively with Solana. Since then, it has come to light that some of the compromised private keys were directly connected to Slope.<\/p>\n\n\n\n<p>Otter Security, SlowMist, and other <a href=\"https:\/\/www.google.com\/search?q=Experts+discover+private+keys+on+Slope+servers%2C+access+unclear&oq=Experts+discover+private+keys+on+Slope+servers%2C+access+unclear&aqs=chrome..69i57.1054j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">blockchain audit<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> and security companies provided support for ongoing investigations.<\/p>\n\n\n\n<p>Robert Chen, the creator of Otter Security, collaborated with Solana and Slope to share insights gained from personal access to the affected resources. Chen stated that some compromised wallets contained private keys that were stored in plaintext on Slope's Sentry logging servers:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>&#8220;The working theory is that an attacker somehow exfiltrated these logs and were able to use this to compromise the users. This is still an ongoing investigation, and current evidence does not explain all of the compromised accounts.&#8221;<\/p><\/blockquote>\n\n\n\n<p>Approximately 5,300 private keys that weren't used in the hack were discovered in the Sentry instance, according to Chen. Users are recommended to relocate money if they haven't already as over half of these addresses still contain tokens.<\/p>\n\n\n\n<p>After being asked by <a href=\"https:\/\/coinscreed.com\/staging\/crypto-stolen-from-solana-might-be-claimed-as-tax-loss-experts.html\" target=\"_blank\" rel=\"noreferrer noopener\">Slope<\/a> to examine the exploit, the SlowMist team reached a similar conclusion. The team also observed that the user's private key and mnemonic phrase were gathered by Slope Wallet's Sentry service and transferred to o7e.slope.finance. Once more, SlowMist was unable to locate any proof demonstrating how the credentials were obtained.<\/p>\n\n\n\n<p>After posting its preliminary findings online, Chainalysis verified that it was conducting a blockchain investigation of the occurrence. The blockchain analysis company also pointed out that individuals who have imported accounts to or from Slope.Finance were most impacted by the exploit.<\/p>\n\n\n\n<p>While the incident exonerates<a href=\"https:\/\/coinscreed.com\/staging\/attack-on-solana-leads-to-compromisation-of-thousands-of-wallets.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Solana<\/a> from taking the most hit from the exploit, it has brought attention to the necessity of wallet providers' auditing services. Before being released, wallets should be subjected to several security company audits, according to SlowMist, who also urged for open source development to boost security.<\/p>\n\n\n\n<p>Compared to decentralized applications, Chen claimed that certain wallet providers have &#8220;flown under the radar&#8221; in terms of security. He wants to see a change in user perception of the connection between wallets and validation from outside security partners as a result of the incident.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The newest steps in the Solana exploit investigation are being unpacked by blockchain analysis companies as teams work to determine how private keys were taken. About 8,000 private keys used to deplete Solana-based wallets were obtained by hackers, and blockchain auditing companies are still trying to determine how they did it. Investigations are still going [&hellip;]<\/p>\n","protected":false},"author":38,"featured_media":32789,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[10619],"class_list":["post-32785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-private-keys-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/08\/22340.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/32785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/38"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=32785"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/32785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/32789"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=32785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=32785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=32785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}