SlowMist: A Solana phishing attack stole $3 million by tampering with the owner permissions of victims' wallets.

PANews reported on December 3rd that SlowMist disclosed on its official WeChat account that it recently received a request for help from a user who claimed to have been targeted by a phishing attack. The user discovered abnormal authorization records in their Solana wallet, attempted to revoke the authorization but was unable to do so, and provided the affected wallet address. On-chain analysis revealed that the user's account owner privileges had been transferred to an address starting with "GKJBEL". Furthermore, the user had already lost assets worth over $3 million USD, and another $2 million USD worth of assets were held in DeFi protocols and could not be transferred (this $2 million USD worth of assets has now been successfully recovered with the assistance of the relevant DeFi platforms).

The victim attempted to transfer funds from the account to their own address to verify authorization, but all transactions failed. This situation is highly similar to the "malicious multi-signature" attacks that frequently occur in the TRON ecosystem. In other words, this attack is not a traditional "authorization theft," but rather the attacker replaced the core permissions (Owner permissions), rendering the victim powerless even if they wanted to transfer funds, revoke authorization, or operate DeFi assets. The funds are "visible," but no longer under their control.

Share to:

Author: PA一线

This content is for informational purposes only and does not constitute investment advice.

Follow PANews official accounts, navigate bull and bear markets together
Recommended Reading
3 hour ago
6 hour ago
6 hour ago
16 hour ago
19 hour ago
2026-01-16 03:15

Popular Articles

Industry News
Market Trends
Curated Readings

Curated Series

App内阅读