Slope Wallet Hack

Approximate loss $4.1M
Solana
Wallet-key compromise

What happened

Beginning August 2, 2022, compromised wallet keys were used to drain Solana users' assets. The Solana Foundation estimated about $4.1 million lost. Investigators found that Slope mobile wallets sent secret material to a privately hosted monitoring service, but later forensic reports could not conclusively link that exposure to every drained wallet.

Technical root cause

Sensitive wallet material entered monitoring logs; the complete key-theft path remains unproven.

How it happened

  1. Slope's mobile application logged sensitive wallet material to its own Sentry deployment.
  2. Attackers signed unauthorized transfers with compromised wallet keys. How they obtained the complete set of keys remained unresolved.
  3. Slope shut down the monitoring service and urged users to move assets to newly generated wallets. Solana's core protocol was not the vulnerable component.

Protocol details

Classification Infrastructure / Other / Frontend & Infrastructure
Protocol Type Exploit/Other
Protocol links Website @Solana

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.