🚨 ATTENTION SNS COMMUNITY & SQUADS USERS 🚨
We’ve spotted a wave of address poisoning attacks specifically targeting Squads users. As an SNS Ambassador, I want to make sure our community stays SAFU. This isn't a protocol breach, but a clever social engineering trick at the UI level.
The Attack Breakdown
• The "Look-Alike" Trick: Attackers are "grinding" public keys to match the first and last characters of your real multisig addresses.
• The Bait: They create new multisigs and add you as a member. These show up in your Squads UI, hoping you’ll accidentally copy the fake vault address or sign a malicious transaction.
• The Good News: Your funds are safe as long as you do not interact with these fake accounts.
How SNS Helps You Stay Safe 🛡️
This attack thrives on the fact that long wallet addresses are hard to read. This is exactly why we use Solana Name Service (.sol).
• Verify with Names, Not Just Keys: While attackers can spoof the first/last characters of a public key, they cannot spoof your unique .sol domain.
• Readable Identity: Use your SNS name to double-check where you are sending funds. It’s much harder to mistake yourteam.sol for a random string of characters.
Action Items for You
1.Ignore & Avoid: If you see a multisig you didn’t create or expect, leave it alone.
2.Full Address Verification: Never trust just the first and last 4 characters. Verify the entire string against your records.
3.Set Defaults: Click the ... next to your real Squads and set them as default. This pins them to the top and separates them from the noise.
4.Use SNS: Resolve your multisig addresses to a .sol name to add an extra layer of visual certainty.
We've identified an address poisoning attack targeting Squads users. We have no evidence of any users being impacted at this time.
Attack vector: Since all public keys are visible onchain, attackers are programmatically creating new multisig accounts that include existing Squads users as members. These multisigs appear in the UI because the program indexes all accounts associated with your key. Additionally, attackers are grinding public keys that match the first and last characters of your real multisig addresses, making fake accounts look legitimate at a glance.
Attacker goal: Get you to mistake a fake multisig for one of your real ones — either by copying its vault address (sending funds to an attacker-controlled account) or by signing a transaction you didn't initiate.
Impact: None, if you don't interact. This is not a protocol vulnerability. The attacker cannot access your funds, execute transactions, or modify your existing multisigs. It is purely a UI-level social engineering attempt.
Action required:
— Ignore and do not interact with any multisig you did not create or weren't added to by your team
— Do not rely on matching the first and last characters of an address to verify it — always verify the full address against your own records
— If you're unsure whether a multisig is legitimate, check with your team before taking any action
— Set your Squads accounts as default — this pins them to the top of your Squad list, making it easy to distinguish your real accounts from anything unfamiliar. We encourage everyone to do this now if you haven't already (click on ... next to your Squad in the Squad list).
UI updates shipping in the next two hours:
— A banner alerting users to this attack
— An alert on any multisig you've never interacted with before
In the next few days we are also shipping a whitelist logic where all new multisig accounts initially go to a pending state requiring you to manually add them to your Squad list.
We'll follow up here with updates as we roll these out.
The next phase of the internet won’t be driven by humans alone, autonomous agents are becoming active participants. And in any digital system, identity is the foundation everything else builds on.
With .sol domain registration now available through @xona_agent Orbit platform, that foundation is starting to take shape.
Agents can secure a unique, verifiable identity at creation, rather than treating it as something to figure out later.
🧵