立刻保护您的项目
借助最大的web3安全提供商来增强您的项目。
CertiK 安全专家将审核您的请求,并尽快与您联系。

2022 Solana Exploits Overview

报告 ·安全报告 ·
2022 Solana Exploits Overview

TL;DR

In 2022, Solana Blockchain has lost approximately $523 Million in stolen funds in exploits.

Introduction

Solana, a public blockchain platform, has suffered 11 significant attacks over the last year resulting in a total loss of ~$523 million. By far the largest incident was the exploit which occurred on the Wormhole Bridge resulting in the loss of $326 million, which is also the second largest exploit which has occurred exploit in terms of lost funds to have occurred this year. Of the 11 incidents, 10 lost over $1 million. You can see the breakdown of these exploits below.

Solana Incidents Image: Breakdown of funds lost by exploit. Source: CertiK

Exploits

Solana had seven major exploits this year including Wormhole, Cashio, Mango Market, Solend, and Optifi. These exploits led to a total profit loss of ~$492 million in user funds. The largest exploit on Solana protocol was the Wormhole incident, which led to a loss of ~$326 million. Attackers exploited a signature verification vulnerability in the Wormhole network to mint 120k Ether on Solana. The hack occurred due to a lack of signature verification authorizations, where the developers used a deprecated function to enable unverified forged signature passes. The second largest exploit on Solana occurred on October 11, 2022, when Mango Markets was exploited by a group of attackers that totaled a loss of $116 million. Attackers manipulated the value of a posted collateral to a higher price. Hackers then took out significant loans against the inflated collateral, which ended up draining Mango’s treasury.

Private Key Compromises

In 2022, $13.5 million has been lost due to private key exploits on the Solana blockchain. The largest private key compromise occurred on 2nd August 2022 when Slope wallet users began to notice that their assets were being transferred out of their wallet. It later became apparent that the private keys of Slope users were stored in plaintext on a third part server which was compromised. This meant that hackers were able to drain approximately 8,000 wallets which led to ~$8 million in losses. The second private key compromise occurred on On 16 December 2022, due to a Trojan virus compromising a key wallet on Raydium Protocol. The exploiter drained multiple liquidity pools which led to approximately $5.5 million worth of assets being stolen.

Private key compromise events are particularly harmful especially when a project has a high degree of centralization. In the case of the Raydium incident, one wallet was able to withdraw liquidity from multiple pools which presents a centralization risk if said wallet is mishandled or compromised. Always check certik.com audits and understand the centralization risks of a project and see what measures the team have taken to mitigated these security issues.

Exit Scams

Users on the Solana blockchain fell victim to multiple exit scams, losing millions to scammers. In 2022, there were four significant exit scams on the Solana blockchain totalling ~$5.3 million of stolen user funds. These exit scams included COPE, Big Daddy Ape Club, Doodled Dragons, and SolFire Finance, with the largest exit scam being SolFire Finance at ~$4.1 million user funds stolen. The SolFire Finance project owner stole all user funds and moved them to the Ethereum via a cross-chain bridge. The project then deleted their GitHub account and Twitter accounts.

Doing your own due diligence on a project is extremely important to avoid being the victim of an exit scam. There are a number of resources you can utilize to help you DYOR. For example, CertiK offers industry leading KYC investigations which mean the team behind a project are thoroughly vetted by skilled investigators and analysts. CertiK have uncovered a KYC actor industry which aims to trick KYC services into passing illegitimate projects. Look for the CertiK KYC badge on certik.com to help you DYOR in investing in trustworthy projects.

Conclusion

This year has been a tough one for DeFi platforms, especially Solana. Projects on Solana suffered multiple costly exit scams and exploits which included key compromises and code vulnerabilities. Protect yourself and your assets by following @CertiKAlert on Twitter to stay up to date on all the latest Web3 security news, and visiting certik.com as part of your due diligence.

For more details on the Solana Blockchain please read our article titled What is Solana?

相关博客

Technical Deep Dive | CertiK Helped Fix a DoS Vulnerability in Solana’s Big-Integer Modular Exponentiation

Technical Deep Dive | CertiK Helped Fix a DoS Vulnerability in Solana’s Big-Integer Modular Exponentiation

This article takes an in-depth look at the importance of blockchain transaction fee models and their critical role in ensuring network security and efficient operation. By comparing the transaction fee models of Ethereum and Solana, it highlights how unsafe transaction pricing can introduce network security risks. The article especially focuses on a compute-unit (CU) accounting error in Solana’s big-integer modular exponentiation syscall discovered and reported by the CertiK team, which could lead to a potential remote DoS attack. It further analyzes Solana’s smart-contract pricing model, PoH-related timing mechanics, and parallel transaction processing, and reproduces the remote DoS process and cost via experiments on a private Solana cluster.

From Foundations to Frameworks: A Look Back at 2025 and the 2026 Crypto Roadmap

From Foundations to Frameworks: A Look Back at 2025 and the 2026 Crypto Roadmap

As we begin 2026, the crypto industry is no longer fighting for the right to exist; instead, it is racing against the legislative clock to finalize the rules of the game before the political tides could shift once again.

The Memecoin Markets of Springfield

The Memecoin Markets of Springfield

A serial rug puller on Solana executed 64 exit scams in under 24 hours, but lost money on more than 95% of them. We analyze their operation through a Simpsons lens.