SlowMist: Beware of Solana Wallet Owner Authority Tampering Attack
BlockBeats News, December 3rd. SlowMist Security Team released a security advisory regarding a recent phishing attack incident. A user fell victim to a phishing attack, resulting in the transfer of the account's Owner permission. The user attempted to revoke the authorization but was unable to do so. The user's assets worth over $3 million were stolen, with an additional $2 million worth of assets stored in a DeFi protocol that could not be transferred (currently, this part of the assets worth around $2 million has been successfully rescued with the assistance of the related DeFi protocol). This attack was not the traditional "authorization theft" but rather a replacement of the core permission (Owner permission) by the attacker, rendering the victim unable to transfer funds, revoke authorization, or operate DeFi assets despite the funds "appearing normal" but being beyond their control.
The attacker exploited two counterintuitive scenarios to successfully deceive the user into clicking:
1. Usually, when signing a transaction, the wallet would simulate the execution result of the transaction. If there were any fund changes, it would be displayed on the user interface. However, the attacker's carefully crafted transaction showed no fund changes;
2. In the traditional Ethereum EOA account, the ownership is controlled by the private key. Users subjectively were unaware that Solana has a feature that can modify account ownership.
SlowMist reminds users to be vigilant when authorizing signatures and to confirm whether there are hidden operations such as modifying high-risk permissions like Owner in them.
You may also like

Stablecoins Finally Find Real Returns: On-Chain Reinsurance Re Explained | Interview with Re Founder Karan Saroya

The AI gamble of mining companies: Valuations enter a phase of differentiation, and it's hard to turn the tide

A letter from Alliance to entrepreneurs: Written on the occasion of Cursor selling for 60 billion dollars

Will MicroStrategy fall into a death spiral? What will the macro trend be in the second half of the year?

Blockchain Capital Partner: The Core Secret of Arbitrage

STRC unanchored by 11%, can the perpetual motion machine of Strategy still operate?

Bitcoin Market Analysis 2026: Can BTC Reach $150K by Year-End?

Bitcoin ETF Outflows Hit a Record $4.4 Billion: What Are Traders Doing With Their Cash?

WEEX App Just Got Smarter – New Tabs for Faster Trades & Easy Asset Management

WEEX All-New Search Features: Find, Trade & Earn Faster Than Ever

Morning Report | Illinois signs the strictest digital asset tax law in the U.S.; RWA tokenization market size surpasses $43 billion, institutions accelerate the migration of on-chain assets

Full version of the debut Q&A! Federal Reserve Chairman Waller: Sticking to the 2% inflation target, establishing five special working groups, individual did not submit the dot plot

From Disruptor to Shadow Market: The Crypto Market is Becoming a Colony of Traditional Finance

Dalio's important long article: How to position in the current market environment?

OKX Star analyzes Binance's competitive advantages: when regulation levels the playing field, competition has just begun

New gameplay for participating in initial offerings on cryptocurrency exchanges

Why Is Bitcoin Down Today? What the Hawkish FOMC Means for SpaceX, Gold and Nasdaq

