{"id":64716,"date":"2023-11-16T07:15:28","date_gmt":"2023-11-16T11:15:28","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=64716"},"modified":"2023-11-16T07:15:33","modified_gmt":"2023-11-16T11:15:33","slug":"certik-exposes-critical-vulnerability-in-solana-saga-phone","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/certik-exposes-critical-vulnerability-in-solana-saga-phone\/","title":{"rendered":"Certik Exposes Critical Vulnerability in Solana Saga Phone"},"content":{"rendered":"\n<p>CertiK, a leading cybersecurity firm, discovered a critical vulnerability in the Solana Saga phone, a smartphone that integrates the Solana Mobile Stack. The flaw allowed assets to be transferred within a minute of obtaining the phone.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"450\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/solana-labs-saga-android-mobile-phone-800x450-1.jpg\" alt=\"Certik Exposes Critical Vulnerability in Solana Saga Phone\" class=\"wp-image-64719\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/solana-labs-saga-android-mobile-phone-800x450-1.jpg 800w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/solana-labs-saga-android-mobile-phone-800x450-1-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/solana-labs-saga-android-mobile-phone-800x450-1-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/solana-labs-saga-android-mobile-phone-800x450-1-18x10.jpg 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/solana-labs-saga-android-mobile-phone-800x450-1-750x422.jpg 750w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p>The Solana Saga phone, a smartphone that claims to offer a secure and seamless Web3 experience, was found to have a serious vulnerability that put more than <strong>2,100 devices<\/strong> at risk since April. <\/p>\n\n\n\n<p>The vulnerability was uncovered by CertiK, a leading cybersecurity firm specializing in blockchain and <a href=\"https:\/\/coinscreed.com\/staging\/smart-contract-security-challenges-and-solutions.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">smart contract audits. <\/a><\/p>\n\n\n\n<p>The Solana Saga phone, an Android-based smartphone introduced by Solana CEO Anatoly Yakovenko in June 2022, is distinguished by its integration of the Solana Mobile Stack (SMS), which features a <em>\u201cSecure Element\u201d<\/em> to manage private keys and bolster the security of Web3 transactions.<\/p>\n\n\n\n<p>However, CertiK discovered that the Secure Element was not as secure as it claimed to be.<\/p>\n\n\n\n<p>The flaw allowed anyone who had physical access to the phone to transfer the assets stored in the SMS wallet within a minute of obtaining the phone without needing to unlock the device or enter the PIN code.<\/p>\n\n\n\n<p>CertiK reported the vulnerability to Solana Labs in October and issued a public alert on <strong>Nov. 15, 2023<\/strong>, urging all Solana Saga phone users to update their firmware to the latest version and transfer their assets to a different wallet as soon as possible.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">In April, we introduced Saga with a clear vision: to put web3 at your fingertips. We continue to work to bring more people into the ecosystem and drive web3\u2019s mobile future. Today, we are reducing the price of Saga to $599.<br><br>Over the past four months, Saga users embraced the\u2026 <a href=\"https:\/\/t.co\/qpC1BHiqZ7\" target=\"_blank\">pic.twitter.com\/qpC1BHiqZ7<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/p>&mdash; Seeker | Solana Mobile (@solanamobile) <a href=\"https:\/\/twitter.com\/solanamobile\/status\/1689305794049634304?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">August 9, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-response-from-solana-labs\">The response from Solana Labs<\/h3>\n\n\n\n<p>Solana Labs acknowledged the vulnerability and thanked CertiK for their responsible disclosure. The studio also released a firmware update that fixed the flaw and improved the security of the SMS wallet. <\/p>\n\n\n\n<p>Solana Labs advised all Solana Saga phone users to install the update and reset their PIN codes.<\/p>\n\n\n\n<p>The blockchain studio also stated that they were not aware of any cases of asset theft or loss due to the vulnerability and that they would compensate any affected users if such cases were reported. <\/p>\n\n\n\n<p>Solana Labs also assured that they would continue to work with CertiK and other security experts to ensure the safety and reliability of the Solana Saga phone and the Solana Mobile Stack.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The outlook for the Solana Saga phone<\/h3>\n\n\n\n<p>Despite the potential of the Solana Saga phone, using it currently feels akin to beta testing, especially for average consumers. <\/p>\n\n\n\n<p>Solana Labs acknowledges this challenge but remains optimistic about the device\u2019s appeal to early adopters and developers.<\/p>\n\n\n\n<p>The Saga phone witnessed a notable price drop from <strong>$1,000<\/strong> to <strong>$599<\/strong> in September. Solana attributed this <strong>$400<\/strong> reduction to a strategic move to foster wider adoption of mobile Web3 and enhance the overall user experience within the Solana mobile community.<\/p>\n\n\n\n<p>Solana Mobile is committed to delivering an excellent welcome experience for Saga users through the genesis token, which is a native token of the SMS wallet that can be used to access various Web3 applications and services. <\/p>\n\n\n\n<p>The Mobile phone also encourages the exploration of Web3 by offering rewards and incentives for using the Solana Saga phone and the Solana Mobile Stack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CertiK, a leading cybersecurity firm, discovered a critical vulnerability in the Solana Saga phone, a smartphone that integrates the Solana Mobile Stack. The flaw allowed assets to be transferred within a minute of obtaining the phone. The Solana Saga phone, a smartphone that claims to offer a secure and seamless Web3 experience, was found to [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":64719,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[10415,10913,17239],"class_list":["post-64716","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-certik-2","tag-solana-labs-2","tag-solana-saga-phone"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/solana-labs-saga-android-mobile-phone-800x450-1.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/64716","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=64716"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/64716\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/64719"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=64716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=64716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=64716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}