SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
Hundreds of sub-threshold transactions drained hot wallets across Ethereum, TRON, Solana, and BSC before funds moved toward Tornado Cash.
Loss
~$8M
Risk
Cross-chain liquidity risk
Confidence
89%
Instant Forensic Report · x402 on Solana
Pay once with SOL via x402 — the machine-to-machine payment protocol on Solana. Full wallet trace, fund flow graph, exploit PoC, and PDF export unlocked instantly.
x402 · HTTP 402 payment required · Solana Mainnet · Demo mode
Reporter Agent synthesis with forensic confidence scoring
The attacker structured withdrawals below alert thresholds across multiple chains, exploiting bridge architecture and complicating recovery through mixing routes.
Bridge and hot-wallet monitoring relied on per-transaction thresholds rather than correlated multi-chain outflow detection.
confidence score
Cross-chain liquidity risk
Attacker path, bridge transfers, token drains, mixer usage
Cross-chain bridge vulnerability and hot-wallet draining
Sub-threshold transaction structuring bypassed automated alerts
NoOnes Solana bridgeEthereum hot walletTRON hot walletBSC hot walletEmergency Bridge
Move funds off Solana
If your assets are at risk on Solana, bridge them to a safer chain immediately via LI.FI — the cross-chain aggregator covering 60+ chains and all major Solana bridges.
From (at risk)
Solana
Bridge to
Best Route via LI.FI
Solana → Ethereum
Mayan Swift • Across • Glacis aggregated
Est. Fee
~$0.50
60+ chains · gasless swaps on Solana · Jito bundles
60+
Chains
$2B+
Volume
20+
Bridges
00:00
NullTrace Scout Agent detects abnormal account, wallet, or market behavior.
00:19
Analyst Agent matches the activity against known Web3 attack signatures.
00:41
Forensics Agent clusters wallets, bridge routes, exchange hops, and mixer exposure.
01:12
Reporter Agent collects researcher warnings and suppresses unverified claims.
03:48
Protocol actions, freezes, recovery updates, and public statements are added to the dossier.
Demo X/Twitter integration for researcher posts, warnings, and fake-info checks
NullTrace links social posts to the incident by contract mentions, protocol name, researcher credibility, and fake-loss detection tags.
SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
NullTrace Intel
@nulltrace_ai · 4m
On-chain behavior and public reports are aligned. Confidence raised after wallet clusters matched the incident pattern.
Maya Chen
@maya_sec · 7m
The important signal is not only the drain. Watch the staging wallets and the small test transactions before the main move.
Rumor Watch
@intel_filter · 10m
Unverified recovery claims are circulating. No confirmed full recovery unless the protocol or tracked wallet flows support it.
suppressed by misinformation filter
SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
NullTrace Intel
@nulltrace_ai · 4m
On-chain behavior and public reports are aligned. Confidence raised after wallet clusters matched the incident pattern.
Maya Chen
@maya_sec · 7m
The important signal is not only the drain. Watch the staging wallets and the small test transactions before the main move.
Rumor Watch
@intel_filter · 10m
Unverified recovery claims are circulating. No confirmed full recovery unless the protocol or tracked wallet flows support it.
suppressed by misinformation filter
Generated incident narration for security leadership
briefing ready · 00:58 · analyst-grade summary