SlowMist: Beware of Solana Wallet Owner Authority Tampering Attack

By: theblockbeats.news|2025/12/03 11:45:55
0
Share
copy

BlockBeats News, December 3rd. SlowMist Security Team released a security advisory regarding a recent phishing attack incident. A user fell victim to a phishing attack, resulting in the transfer of the account's Owner permission. The user attempted to revoke the authorization but was unable to do so. The user's assets worth over $3 million were stolen, with an additional $2 million worth of assets stored in a DeFi protocol that could not be transferred (currently, this part of the assets worth around $2 million has been successfully rescued with the assistance of the related DeFi protocol). This attack was not the traditional "authorization theft" but rather a replacement of the core permission (Owner permission) by the attacker, rendering the victim unable to transfer funds, revoke authorization, or operate DeFi assets despite the funds "appearing normal" but being beyond their control.

The attacker exploited two counterintuitive scenarios to successfully deceive the user into clicking:

1. Usually, when signing a transaction, the wallet would simulate the execution result of the transaction. If there were any fund changes, it would be displayed on the user interface. However, the attacker's carefully crafted transaction showed no fund changes;

2. In the traditional Ethereum EOA account, the ownership is controlled by the private key. Users subjectively were unaware that Solana has a feature that can modify account ownership.

SlowMist reminds users to be vigilant when authorizing signatures and to confirm whether there are hidden operations such as modifying high-risk permissions like Owner in them.

You may also like

The impact of OUSD on Circle, Tether, and Paxos: not a single negative factor, but a more complex reshaping of competition

OUSD will not be the last new competitor; Circle needs to respond more actively in terms of products, distribution, and ecosystem collaboration.

Li Feifei's latest long article: When video generation, robots, and NVIDIA all claim to be world models, we need a taxonomy

Language gives machines a way to talk about the world. The world model is the means by which machines ultimately understand, imagine, reason, and interact with it.

Blaming the desolation of the cryptocurrency world on the rise of AI is a form of intellectual laziness

The emergence of giants signifies a mature business model. Although it will reduce speculative space, there is also enough room for error, allowing for the continuous emergence of new forces.

Strategy Founder: The Next 10 Years of Bitcoin

In the next decade, the biggest evolution of Bitcoin is precisely "responding to change with invariance." The four-year cycle is giving way to capital flows such as ETFs, corporate and sovereign reserves, and bank credit, while digital credit and digital currency will grow layer upon layer on top of...

Forbes Special Report: Stablecoin cross-border payments are faster now, but not cheaper yet

Cross-border payments using stablecoins are rapidly expanding, bringing speed and accessibility, but due to insufficient institutional liquidity, they have not yet delivered on their promised cost savings. The technology has been validated, and regulations are improving, but the industry has not yet...

A valuation of 8 billion dollars, doubling in 8 months! What makes the crypto-friendly bank Erebor Bank stand out?

Erebor is a high-profile experiment taking place at the intersection of banking, cryptocurrency, and industrial policy.

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com