Slope Wallet Hack
What happened
Beginning August 2, 2022, compromised wallet keys were used to drain Solana users' assets. The Solana Foundation estimated about $4.1 million lost. Investigators found that Slope mobile wallets sent secret material to a privately hosted monitoring service, but later forensic reports could not conclusively link that exposure to every drained wallet.
Sensitive wallet material entered monitoring logs; the complete key-theft path remains unproven.
How it happened
- Slope's mobile application logged sensitive wallet material to its own Sentry deployment.
- Attackers signed unauthorized transfers with compromised wallet keys. How they obtained the complete set of keys remained unresolved.
- Slope shut down the monitoring service and urged users to move assets to newly generated wallets. Solana's core protocol was not the vulnerable component.
Protocol details
Evidence
- report Slope Wallet Sentry Vulnerability - Digital Forensics and Incident Response Report slope-finance.medium.com
- analysis 8/2/2022 Slope Wallet Incident Update solana.com
- analysis Web Archive web.archive.org
- analysis Website reference cnbc.com
- analysis Website reference coindesk.com
- analysis Website reference techcrunch.com
- analysis DeFiLlama defillama.com
- analysis Analysis of a Large-scale Attack on Solana (Part 2) slowmist.medium.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.