Slope: No Vulnerabilities Found Other Than Previous Sentry Server Implementation Issues

Solana ecosystem wallet Slope updates the progress of the attack investigation stating that no additional vulnerabilities were found during the investigation and multi-party review, and that independent audit findings include. 1. There was a vulnerability in the Sentry Service implementation on Slope Wallets on mobile from July 28th to August 3rd that inadvertently logged sensitive data in cases where the apps generated an error event. 2. There is no evidence that all security layers (e.g., transmission and storage) were compromised. All the transmission to the Sentry server is protected through HTTPS end-to-end encryption, and access to the Sentry server is controlled through 3-factor authentication. 3. As confirmed in previous interim reports from Ottersec, the investigation team has cross-compared all hacked addresses (9,232 addresses in total) vs. all exposed addresses from the vulnerability in the Sentry database: the number of all hacked addresses is larger than the total number of addresses ever exposed from the Sentry server. A fraction (1,444 addresses) of the total exposure from the Sentry server has been confirmed drained in cross-comparison.
Source

Wallet

DeFi

Security Incidents

Related News
North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms
Term Finance recovers $1 million of $1.6 million loss to oracle configuration error Term Finance recovers $1 million of $1.6 million loss to oracle configuration error
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
Wildcat, the decentralized credit platform built by Crypto Twitter mainstay Laurence Day, launches new version on Ethereum Wildcat, the decentralized credit platform built by Crypto Twitter mainstay Laurence Day, launches new version on Ethereum
Latest News More More
2 Days Ago Tether plans further Bitcoin mining expansion in South America with Adecoagro tie up
3 Days Ago JPMorgan's blockchain unit tests new carbon credit tokenization application with S&P Global
6 Days Ago Ethereum community plans onchain ‘time capsule’ to mark 10th anniversary of network’s genesis block
June 25 Circle's post-IPO stock surge pushes market cap near Coinbase and USDC
June 20 Kraken offers bitcoin ‘staking’ yield via Babylon without wrapping or lending
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open