• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Scam-as-a-Service on Solana Identified: Here’s What You Need to Know

February 12, 2024
in Australian Crypto News
Reading Time: 3min read
0 0
A A
0
Scam-as-a-Service on Solana Identified: Here’s What You Need to Know
0
SHARES
5
VIEWS
ShareShareShareShareShare
  • Crypto security firm Blowfish has identified a new type of attack impacting Solana, dubbing them ‘bitflip attacks’.
  • ‘Bitflip attacks’ allow seemingly legitimate transactions to be altered after they’ve been cryptographically signed, to drain users’ wallets.
  • Scripts to run ‘bitflip attacks’ are being sold on scam-as-a-service marketplaces, making them much easier to run.
  • Blowfish said it is currently auto-blocking all these attacks on the Solana network as it works toward implementing a permanent solution.

Crypto security firm, Blowfish, has identified a novel class of attack impacting the Solana ecosystem, which it has dubbed a ‘bitflip attack’. Blowfish considers these attacks to be especially dangerous as they allow ostensibly legitimate transactions to be modified in a post-hoc fashion to later drain users’ wallets by ‘flipping’ specific bits to change transaction details.

Worryingly, scripts to run these attacks are being sold on ‘scam-as-a-service’ marketplaces, allowing virtually anyone to run them, even those with little technical expertise.

What The (Bit) Flip?

In an X thread posted on Saturday, Blowfish described these new attacks, explaining it had identified two new ‘drainer’ scripts available on scam marketplaces named ‘Aqua’ and ’Vanish’, that were using the ‘bitflip’ attack.

This is how it works:

First, the victim signs a seemingly benign transaction. When the drainer receives the signature, they hold onto it temporarily.

Then, via a separate transaction, they flip the dApp’s conditional; it goes from appearing to send SOL to taking it instead.

— Blowfish (@blowfishxyz) February 9, 2024

Essentially, a ‘bitflip’ attack is possible because dApps running on Solana can be given permission to submit transactions and these transactions can include conditional code to either transfer money into a wallet or drain money out of a wallet. 

‘Bitflip’ drainers can flip this conditional even after a transaction has been cryptographically signed. This means that seemingly legitimate transactions can be changed after the fact by these ‘bitflip’ drainer scripts to drain users’ wallets.

Solution In The Works 

Blowfish says it’s been aware of these attacks for a while and has been working with its partners to mitigate their impact. According to Blowfish all these ‘bitflip’ attacks on the Solana network are currently being ‘auto-blocked’ as they work towards implementing a more permanent solution.

The good news is that Blowfish has been aware of this potential risk and strategizing with our partners about how to mitigate this attack for a long time.

In <12 hours, we’ve put defenses & monitoring in place, and all such attacks are currently auto-blocked by us.

— Blowfish (@blowfishxyz) February 9, 2024

The past week has been rough for Solana. ‘Bitflip’ attack revelations are just the latest piece of bad news to hit the network—last week it experienced a significant outage after a relatively long period of uninterrupted uptime in the wake of the high-profile Jupiter airdrop.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Signs Point to Fresh BCH Rally Ahead

Next Post

Ethereum Co-Founder 22K ETH Transfer Sparks Price Speculation

Next Post
Ethereum Co-Founder 22K ETH Transfer Sparks Price Speculation

Ethereum Co-Founder 22K ETH Transfer Sparks Price Speculation

You might also like

XRP Price Prediction: Quiet in Price Movement, Loud in Building and Participation

XRP Price Prediction: Quiet in Price Movement, Loud in Building and Participation

June 23, 2026
BOJ deputy warns on inflation as Polymarket puts 2026 Fed hike odds at 66%

May inflation hits 4.1% as Polymarket sees 79% odds of zero Fed cuts in 2026

June 26, 2026
Chainlink World Cup Role Puts Oracle Settlement In Spotlight

Chainlink Marks Two Highest Network Growth Days of 2026 Amid

June 27, 2026
Ethereum Triangle Breakdown Adds Pressure On Its Recovery Outlook

Ethereum Foundation Executive Says MEV Is Becoming Crypto’s

June 23, 2026
Polymarket Vendor Breach Opens Door for $3M Crypto Heist

Polymarket Vendor Breach Opens Door for $3M Crypto Heist

June 26, 2026
Ethereum Price Prediction: The notorious jaredfromsubway.eth Drained, Vitalik Buterin was a Victim, and The Quest to Make ETH Saver and Faster

Ethereum Price Prediction: The notorious jaredfromsubway.eth Drained, Vitalik Buterin was a Victim, and The Quest to Make ETH Saver and Faster

June 22, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Drone hits raise Russia strain; Polymarket sees 11.5% chance Putin exits by 2026

Drone hits raise Russia strain; Polymarket sees 11.5% chance Putin exits by 2026

June 29, 2026
Year-end odds on Israel–Indonesia ties shift in Polymarket

Supreme Court rulings near as Polymarket cuts Newsom 2028 Dem odds to 20.55%

June 28, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.