Thank you again to @osec_io + @SlowMist_Team for their efforts assessing/reviewing the breach.
They have now both published full reports (below):
▪️ OtterSec - https://t.co/QCjHfT6oJR
▪️ SlowMist - https://t.co/BGDg5maThw
We will also publish an internal Slope factsheet tomorrow.
Slope Update - 13 Aug
▪️The release of the auditing statements has been postponed as they are still in progress. We will link to both when they become available.
Slope Update - 12 Aug
▪️ Our auditors @osec_io & @SlowMist_Team will publish their audit results today. We will link the reports when they're made public
▪️ Huge thank you to the @Solrazr_App team for forwarding a very meaningful clue towards further tracing the hacker addresses
See below for our official statement on the breach situation (now posted to our Medium).
We empathize with everyone affected, and are doing our best to solve and rectify the situation.
https://t.co/E9xrKbdLOy
Hackers - please see below for our bounty offer in return for the safe return of our users' assets.
Wallet address: DyQ96GwjkHkGSzYEB4NaPk2NxsXyRTMNHKJQd3fziABf
Nevertheless, until the root cause is found, we invite all Slope users to create a new seed phrase in a new wallet.
Updates will be shared as the investigation in both the root causes and the asset recovery proceed.
A huge thank you to @osec_io for their contribution so far!
Additional information:
The server-side logging was removed as soon as the vulnerability was discovered.
At this moment, 1444 of the 9223 (15%) wallets affected could potentially be traced back to this vulnerability.
Continued ⬇️
Over $4M was drained from Solana wallets over the past 2 days. We’ve been working directly with @solana and @slope_finance to investigate.
Here’s what we found.
We are working together with our auditing partners and the Solana foundation to uncover any potential additional attack vectors.
Relevant law enforcement agencies have been informed in order to proceed with criminal investigations against the attackers.
Engineers from multiple ecosystems, with the help of several security firms, are investigating drained wallets on Solana. There is no evidence hardware wallets are impacted.
This thread will be updated as new information becomes available.
To all those currently affected by the breach on Solana, please know we are actively working to sort out the issue as rapidly as possible and rectify best we can.
We will be in touch as soon as we have answers.