SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
Phishing transactions abused Solana owner reassignment, giving attacker-controlled programs delayed control over victim accounts.
Loss
$3M+
Risk
User-level persistent control risk
Confidence
94%
Instant Forensic Report · x402 on Solana
Pay once with SOL via x402 — the machine-to-machine payment protocol on Solana. Full wallet trace, fund flow graph, exploit PoC, and PDF export unlocked instantly.
x402 · HTTP 402 payment required · Solana Mainnet · Demo mode
Reporter Agent synthesis with forensic confidence scoring
Victims signed deceptive transactions disguised as approvals, mints, or DApp interactions. The transaction silently reassigned account owner permissions to an attacker-controlled program.
Wallet UX did not make owner reassignment risk obvious enough before signing, and users could approve dangerous native-account changes without clear simulation.
confidence score
User-level persistent control risk
Attacker path, bridge transfers, token drains, mixer usage
Owner permission reassignment through deceptive wallet signing
Legitimate Solana account ownership mechanics abused by phishing flows
Victim token accountsAttacker owner programWallet signing UXDeFi positionsEmergency Bridge
Move funds off Solana
If your assets are at risk on Solana, bridge them to a safer chain immediately via LI.FI — the cross-chain aggregator covering 60+ chains and all major Solana bridges.
From (at risk)
Solana
Bridge to
Best Route via LI.FI
Solana → Ethereum
Mayan Swift • Across • Glacis aggregated
Est. Fee
~$0.50
60+ chains · gasless swaps on Solana · Jito bundles
60+
Chains
$2B+
Volume
20+
Bridges
00:00
NullTrace Scout Agent detects abnormal account, wallet, or market behavior.
00:19
Analyst Agent matches the activity against known Web3 attack signatures.
00:41
Forensics Agent clusters wallets, bridge routes, exchange hops, and mixer exposure.
01:12
Reporter Agent collects researcher warnings and suppresses unverified claims.
03:48
Protocol actions, freezes, recovery updates, and public statements are added to the dossier.
Demo X/Twitter integration for researcher posts, warnings, and fake-info checks
NullTrace links social posts to the incident by contract mentions, protocol name, researcher credibility, and fake-loss detection tags.
SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
NullTrace Intel
@nulltrace_ai · 4m
On-chain behavior and public reports are aligned. Confidence raised after wallet clusters matched the incident pattern.
Maya Chen
@maya_sec · 7m
The important signal is not only the drain. Watch the staging wallets and the small test transactions before the main move.
Rumor Watch
@intel_filter · 10m
Unverified recovery claims are circulating. No confirmed full recovery unless the protocol or tracked wallet flows support it.
suppressed by misinformation filter
SlowMist Research
@slowmist_team · 2m
Solana account permission changes need clear wallet simulation. Users should inspect owner reassignment instructions before signing.
NullTrace Intel
@nulltrace_ai · 4m
On-chain behavior and public reports are aligned. Confidence raised after wallet clusters matched the incident pattern.
Maya Chen
@maya_sec · 7m
The important signal is not only the drain. Watch the staging wallets and the small test transactions before the main move.
Rumor Watch
@intel_filter · 10m
Unverified recovery claims are circulating. No confirmed full recovery unless the protocol or tracked wallet flows support it.
suppressed by misinformation filter
Generated incident narration for security leadership
briefing ready · 00:58 · analyst-grade summary