Solana Blockchain Mass Theft Analysis: Slope Wallet Sentry Leaks Mnemonic Phrases
Background Overview
On August 3, 2022, a large-scale theft occurred on the Solana blockchain, where a large number of users had their SOL and SPL tokens transferred without their knowledge. The Slow Mist Security Team tracked and analyzed this incident, investigating everything from on-chain behavior to off-chain applications, and has now made new progress.
The Slope Wallet team invited the Slow Mist Security Team to analyze and follow up together. After continuous tracking and analysis, data provided by the Solana Foundation showed that nearly 60% of stolen users used Phantom Wallet, about 30% of addresses used Slope Wallet, and the remaining users used Trust Wallet, etc. Both iOS and Android versions of the applications had corresponding victims, so we began to focus on analyzing potential risk points in wallet applications.
Analysis Process
While analyzing Slope Wallet (Android, Version: 2.2.2), we found that Slope Wallet (Android, Version: 2.2.2) used Sentry services. Sentry is a widely used service, running under the o7e.slope.finance domain. When creating a wallet, it would send sensitive data such as mnemonic phrases and private keys to https://o7e.slope.finance/api/4/envelope/.

Continuing the analysis of Slope Wallet, we found that in Version: >=2.2.0 packages, the Sentry service would send mnemonic phrases to o7e.slope.finance, while Version: 2.1.3 did not show any behavior of collecting mnemonic phrases.

Slope Wallet historical version download: https://apkpure.com/cn/slope-wallet/com.wd.wallet/versions
Slope Wallet (Android, >= Version: 2.2.0) was released on and after 2022.06.24, so those affected are users who used Slope Wallet (Android, >= Version: 2.2.0) on and after 2022.06.24. However, according to feedback from some victims, they did not know about Slope Wallet and had never used Slope Wallet.
Therefore, according to the statistics from the Solana Foundation, the mnemonic phrases of about 30% of victim addresses may have been collected and sent by the Slope Wallet (Version: >=2.2.0) Sentry service to the Slope Wallet https://o7e.slope.finance/api/4/envelope/ server.
But the other 60% of stolen users used Phantom Wallet — how were these victims stolen from?
In the analysis of the Phantom (Version:22.07.11_65) wallet, we found that Phantom (Android, Version:22.07.11_65) also uses Sentry services to collect user information, but no obvious behavior of collecting mnemonic phrases or private keys was found. (The Slow Mist Security Team is still analyzing the security risks of Phantom Wallet’s historical versions.)
Open Questions
The Slow Mist Security Team is still continuously collecting more information to analyze the cause of the other 60% of stolen users being hacked. If you have any ideas, you are welcome to discuss them with us. We hope to contribute our modest efforts to the Solana ecosystem. The following are some open questions identified during the analysis process:
- Is the behavior of Sentry services collecting user wallet mnemonic phrases a widespread security issue?
- Phantom uses Sentry — will the Phantom Wallet be affected?
- What is the cause of the other 60% of stolen users being hacked?
- As Sentry is a very widely used service, could Sentry’s official team have been compromised? Could this have led to targeted attacks against the cryptocurrency ecosystem?
Reference Information
Known attacker addresses:
Htp9MGP8Tig923ZFY7Qf2zzbMUmYneFRAhSp7vSg4wxVCEzN7mqP9xoxn2HdyW6fjEJ73t7qaX9Rp2zyS6hb3iEu5WwBYgQG6BdErM2nNNyUmQXfcUnB68b6kesxBywh1J3nGeEccGJ9BEzVbVor1njkBCCiqXJbXVeDHaXDCrBDbmuy
Victim addresses: https://dune.com/awesome/solana-hack
Solana Foundation statistics data:
https://www.odaily.news/newsflash/294440https://solanafoundation.typeform.com/to/Rxm8STIT