Solfire Hack
Incident Overview
Solfire executed rug pull by withdrawing assets from the Solfire hot wallet.
Addresses behind the rug pull:
https://solscan.io/account/D6RBPLyUYhUE98rWZrewSkpmSDLypGRoGV4EqvGKkvym
https://solscan.io/account/8XnyGsVNGFWQ2UYAzwj8gqJsCETMzmbY6ZFTqHpRWfy
Funds were stolen from Solfire hot wallet:
https://solscan.io/account/4QSQiBquEZXhLJNHNR6CjKEFWkgmtfcbTjdqHZgZErLn
The list of stolen funds:
- 6.3848 BTC
https://solscan.io/tx/4cdwKrEqcv1EB8oXhJw2Udmww8ySkPh7m3RMLFciWSbSE84oDZmRxeDBCR32XeVYWmF8zodpw4sNxrmJbkCwPTc2
- 104.86 soETH
https://solscan.io/tx/26AnPkNQ6VQaPJ4qyf1AwumEiSnQkXJpM3dhJe5cSqdcPFTkJjMgfojGXxME8QG6CkwAbFCMWLQMscbcDnNHSs4D
- 4,414.47 SOL
https://solscan.io/tx/2vEBhU4F5zZjL65JWkc7CFUZamU9rqpEBbPjugEoSLJ8WJGKBWvYWYUUtRapUtS5kFaF6YR3amCqPJhDBB7VaCrt
- 1,537,822.99 USDT
https://solscan.io/tx/2wcJUbWc4XiCcwrX3sm92XVCxmNEJH27Jo1idJ8N59313BXfqzT8QJj6szeRTekmns9JXjQzbpTKmeR6UFCCky4r
- 299,702.9 USDC
https://solscan.io/tx/5Q2xciZggPc9Ycmrs7XM33AbtAvTEiCHfBDS2MeSgV3ihYKKAc9nXhJ9r5NX3xnmb7pV8Y6hy6xkgx1SPCipa6bp
- 4,030.4 mSOL
https://solscan.io/tx/48r9KhG6N7jbK1wjPR2DnSAGjrKkEfXLRwtX5Q7af3jyQ5BKq7K5Y4BaHLMCtWQTwKgi65V9wx3AMZY2fYhkL9Ln
- 1,457.89 LUNA
https://solscan.io/tx/2roQu6zjy6wCuJK72eQeDHw1ojaA5WwtreYMcSq4okjfsrebXtngsxd5ub3ZZphEy5XFMg8SPjMsGrqU3hJSvSJv
- 26,347.69 RAY
https://solscan.io/tx/QauQooTafdiW2TqoWA4an7owW3fzCDTzWfuDXxDNz2t5eQAVtf2R1QKxBJ1fwB4SFwSme4zNakNzoaRpmSgc5e9
- 46,110.45 SRM
https://solscan.io/tx/zLHjtcwZnGRZfUYqsXF55npe6ebpju2hYfZyPejT8j1dFMuJBu5Q39BPfRgb74z1xtu7wbx6m4EMwZFGLShS8fm
- 830,270.48 SBR
https://solscan.io/tx/3dVq6Z5kddj51LhPesBz8Un4KD6i7e7MVDDvbLqbnnw93mNwzU1Uh34kS8v38g5MCp9MqmaU33yMyXwKD1Er6D2g
Initial gas funding was performed through the following wallet and then funds were bridged to Solana:
https://etherscan.io/address/0xe8032c02…c97f18
Stolen funds have arrived in the next wallets:
https://etherscan.io/address/0xc5afc6c1…044ec5
https://etherscan.io/address/0x1e669254…d66ff7
Part of stolen funds was deposited into Curve pool:
https://etherscan.io/tx/0x6719f05a…adf292
FIRE tokens circulation supply was sent to this address:
https://solscan.io/account/3SfihoLDctTc7fna3akRMkVuSFrhBkCzVv6scBJnjQSF#splTransfers
The liquidity from the pair was removed at:
https://solscan.io/tx/5X8BeUDax4s2k4YywMrp8Dj2EJCiH3RcBw99X51kqfw2yJL3ECqGveuvCyDzaR6a9xGBdShKMaUXdSJKVQgpz57i
https://solscan.io/tx/5QeajKs6shGXXPqUB5xxGXhjEXaK9pUvpvwzBBda48bMPzDcdW1UD8a1hhTSkMkQht71Go7hKGP521egKCSMvLo9
https://solscan.io/tx/36GYywPbYSxZcMigk9Ysdoz32kXqUywfJMP8qHgkDt271qhUSkdZWQPr7jWKUpDwwh3jEfH8MARdY7JAARHp7iNf
https://solscan.io/tx/39TKL9PyJ7A9FBrgeJZjbYtNGth85vWYpEuNPJ7BLuoNzDMz2aMjSbVHVf8SKcXQe24EyzithHPwKU38DV27951x
https://solscan.io/tx/3ugpapQE7JT8U7yrKpidTFW4YhqZ2f9Gpr7QvRFeXmvWC9MLasdy1K7mU8x86VE7LNtx7ZU4daA1NdHXgxjtGczn
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Solfire, these are the critical security checks that could have prevented this incident (January 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Solfire
The Solfire hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.