• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Scam-as-a-Service on Solana Identified: Here’s What You Need to Know

February 12, 2024
in Australian Crypto News
Reading Time: 3min read
0 0
A A
0
Scam-as-a-Service on Solana Identified: Here’s What You Need to Know
0
SHARES
5
VIEWS
ShareShareShareShareShare
  • Crypto security firm Blowfish has identified a new type of attack impacting Solana, dubbing them ‘bitflip attacks’.
  • ‘Bitflip attacks’ allow seemingly legitimate transactions to be altered after they’ve been cryptographically signed, to drain users’ wallets.
  • Scripts to run ‘bitflip attacks’ are being sold on scam-as-a-service marketplaces, making them much easier to run.
  • Blowfish said it is currently auto-blocking all these attacks on the Solana network as it works toward implementing a permanent solution.

Crypto security firm, Blowfish, has identified a novel class of attack impacting the Solana ecosystem, which it has dubbed a ‘bitflip attack’. Blowfish considers these attacks to be especially dangerous as they allow ostensibly legitimate transactions to be modified in a post-hoc fashion to later drain users’ wallets by ‘flipping’ specific bits to change transaction details.

Worryingly, scripts to run these attacks are being sold on ‘scam-as-a-service’ marketplaces, allowing virtually anyone to run them, even those with little technical expertise.

What The (Bit) Flip?

In an X thread posted on Saturday, Blowfish described these new attacks, explaining it had identified two new ‘drainer’ scripts available on scam marketplaces named ‘Aqua’ and ’Vanish’, that were using the ‘bitflip’ attack.

This is how it works:

First, the victim signs a seemingly benign transaction. When the drainer receives the signature, they hold onto it temporarily.

Then, via a separate transaction, they flip the dApp’s conditional; it goes from appearing to send SOL to taking it instead.

— Blowfish (@blowfishxyz) February 9, 2024

Essentially, a ‘bitflip’ attack is possible because dApps running on Solana can be given permission to submit transactions and these transactions can include conditional code to either transfer money into a wallet or drain money out of a wallet. 

‘Bitflip’ drainers can flip this conditional even after a transaction has been cryptographically signed. This means that seemingly legitimate transactions can be changed after the fact by these ‘bitflip’ drainer scripts to drain users’ wallets.

Solution In The Works 

Blowfish says it’s been aware of these attacks for a while and has been working with its partners to mitigate their impact. According to Blowfish all these ‘bitflip’ attacks on the Solana network are currently being ‘auto-blocked’ as they work towards implementing a more permanent solution.

The good news is that Blowfish has been aware of this potential risk and strategizing with our partners about how to mitigate this attack for a long time.

In <12 hours, we’ve put defenses & monitoring in place, and all such attacks are currently auto-blocked by us.

— Blowfish (@blowfishxyz) February 9, 2024

The past week has been rough for Solana. ‘Bitflip’ attack revelations are just the latest piece of bad news to hit the network—last week it experienced a significant outage after a relatively long period of uninterrupted uptime in the wake of the high-profile Jupiter airdrop.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Signs Point to Fresh BCH Rally Ahead

Next Post

Ethereum Co-Founder 22K ETH Transfer Sparks Price Speculation

Next Post
Ethereum Co-Founder 22K ETH Transfer Sparks Price Speculation

Ethereum Co-Founder 22K ETH Transfer Sparks Price Speculation

You might also like

Judge Freezes Controversial Bid to Claim US$234 Billion in Dormant Bitcoin Wallets

Judge Freezes Controversial Bid to Claim US$234 Billion in Dormant Bitcoin Wallets

June 8, 2026
Ethereum Breakdown Warning: This Key Level Could Trigger More Downtrend

Ethereum Breakdown Warning: This Key Level Could Trigger More Downtrend

June 7, 2026
Cardano’s Most Important Analytics Platform Is Shutting Down After Losing 5 Executives in One Year

Cardano’s Most Important Analytics Platform Is Shutting Down After Losing 5 Executives in One Year

June 3, 2026
XRP Price Climbs Off Recent Lows With Fresh Upside Momentum

XRP Price Climbs Off Recent Lows With Fresh Upside Momentum

June 8, 2026
Bitcoin Price Prediction: Florida’s Crypto Bill and $198B U.S. Surplus Boost Market Outlook

Senate Returns With Clarity Act: CBDC Blocked, Stablecoins Win

June 2, 2026
Is It Time To Sell? Bitcoin Price Enters Redistribution Phase That Previously Led To A 78% Crash

Analyst Who Predicted the Bitcoin Crash Says Price Could Reach $40,000, Here’s When

June 6, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

XRP Price Could Explode After Tokenization Deal With Fund Manager

XRP Price Prediction: Only BTC and XRP Have Survived the Top 10 Since 2014

June 8, 2026
XRP To $1 Or A Violent Reversal? Analyst Says Liquidity Setup Is Flashing

XRP To $1 Or A Violent Reversal? Analyst Says Liquidity Setup Is Flashing

June 8, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.