CryptoReal
CASE FILE — Aug 3, 2022

The Phantom-Slope Wallet Drain - Tracing Solana's $5.3M Mass Key Compromise

A sudden, indiscriminate attack tends to produce the same reaction every time: panic first, then suspicion, as nobody can be sure who's already been hit and who's next.

Roughly 8,000 addresses on Solana were compromised in total, with combined losses of about $5.3 million.

Reports of drained wallets started spreading on Twitter shortly after 11pm UTC the previous night, with victims watching SOL and USDC move directly into attacker-controlled wallets. The first fear was that this pointed to a network-level bug that could implicate every Solana account, not just a subset.

That worst-case scenario didn't hold up once the drained totals were tallied — the damage, while serious, wasn't existential for the network. The precise root cause remained unconfirmed, though several clues had surfaced by the time reporting caught up with events. Uncertainty, predictably, gave rise to a wave of competing theories, and separating credible leads from noise proved difficult. (Credit for tracking developments to OtterSec and CIA Officer.)

What actually happened

The earliest reports centered on missing funds from Phantom wallet users, quickly followed by near-identical reports from Slope wallet users — with mobile wallet holders making up most of those affected.

Investigators established early on that the compromised addresses had signed the outgoing transfers themselves, ruling out a straightforward phishing-for-approval scenario. The more troubling implication: private keys for the affected wallets had actually been exposed somewhere.

That left several open questions — a browser extension leak? Mobile malware? Some speculated an ECDSA nonce reuse flaw, similar to what caused the Anyswap exploit (Anyswap has since become Multichain), though that theory ran into a problem: such an attack would require each affected address to have made at least two transactions, and it seemed improbable that all roughly 8,000 wallets fit that pattern.

A separate report of a large-scale malware campaign targeting GitHub repositories briefly circulated as a possible connection, before being dismissed as unrelated and overstated.

With each competing explanation adding to the noise, and the community struggling to pin down a cause, hardware wallets and centralized exchanges came to be viewed as the only reliably safe options in the interim. Meanwhile, the count of drained accounts — sitting around 8,000 — kept climbing throughout.

Sums referenced in this case file

Notably, at least one Ethereum address was also hit, possibly because a seed phrase had been reused across both chains.

Between leaky extensions, a possible mobile malware wave, and a potential cryptographic flaw, no single explanation had been confirmed. Solana co-founder Anatoly Yakovenko later pointed to an "iOS supply chain attack" as the likely source, specifically affecting users whose keys had been imported or generated on a mobile device. Affected users were directed to submit a report through a form set up by the Solana Foundation to help consolidate information.

Chasing the exploiters

Attention has also turned to the wallets holding the stolen funds. One self-described whitehat reportedly DDoSed the attacker directly, slowing their operation but knocking block explorers offline as a side effect. Separately, another anonymous user claims to have unmasked one exploiter's IP address by sending them an NFT containing a tracking image that logged the request when opened.

Four exploiter addresses have been identified on Solana, together holding $5,276,392.50 at time of writing:

A public dashboard breaks the stolen funds down by asset — roughly 50% USDC, 35% SOL, and 15% other tokens — and shows the three largest individual wallet losses at $246,000, $125,000, and $100,000.

What it means for trust in Solana

Solana has built much of its reputation on claims of speed and low fees — claims rekt.news has previously argued are somewhat overstated. Whether an attack of this breadth erodes user confidence in the network's security remains an open question.

Technically, the incident has nothing to do with Solana's core protocol, but that distinction is unlikely to matter much to retail users who now associate the network with the headline. SOL's price dipped noticeably as the news broke, though there was no full-blown crash, suggesting the immediate panic has largely subsided.

The broader market remains on edge regardless — this followed just a day after the chaotic Nomad Bridge exploit, and the rumor-driven response to this incident has echoed that same disorder. It's little surprise that crypto Twitter (and this outlet) has an appetite for a good conspiracy theory in moments like this.

Episodes like this are a reminder of basic security habits that get overlooked when short-term gains are the priority: use a hardware wallet, spread risk across wallets, and be cautious chasing yield through bridges that carry outsized risk. Whether that's ever truly sufficient protection is a separate question.

Solana
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.