BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home BUSINESS

Solana Hacked Again: Scam-as-a-Service Tools Target Users’ Funds

Matoy by Matoy
February 12, 2024
in BUSINESS, CRYPTO, INVESTING
Reading Time: 3 mins read
5
SHARES
77
VIEWS
Share on XShare in TelegramShare on Reddit
  • Solana wallet drainers utilize bit-flip attacks to change transaction data after signing, allowing theft of users’ funds.
  • Two new drainers, Aqua and Vanish, are being sold on scam-as-a-service sites and target Solana dApps.
  • Solana faces increasing draining attacks, with some exploit kits having thousands of members. Users should only interact with trusted sources.

Web3 security firm Blowfish has identified two new Solana wallet drainers that can steal users’ funds through bit-flip attacks, according to Web3 security firm Blowfish. These tools are being offered for sale on scam-as-a-service marketplaces.

How the Drainers Work

The drainers, named Aqua and Vanish, work by modifying a conditional statement within a transaction’s on-chain data, even after the transaction has been signed by the user with their private key.

Specifically, the drainers target decentralized apps (dApps) that have been granted authority to submit transactions on the user’s behalf. If the dApp’s on-chain program contains a conditional that checks if funds should be sent to the user or drained from their account, the drainer can flip that conditional at any time after the transaction is signed.

ICYMI: Security firm Blowfish (@blowfishxyz) uncovers two new Solana wallet drainers

– Aqua

– Vanish

Both being sold on scam marketplaces

— BlockNews.com (@blocknewsdotcom) February 12, 2024

This allows the drainer to temporarily hold the transaction, then submit it later with the conditional flipped to drain funds instead of sending them. The user is unaware of the change since their valid signature is still applied.

The Bit-Flip Attack

The drainers utilize a bit-flip attack, which changes the value of some bits in the encrypted data to manipulate the system. The drainer can modify the transaction without knowing the encryption key. Flipping specific bits in a predictable way allows the data to be decrypted differently than the user intended.

Drainers Targeting Solana on the Rise

Solana has faced an increasing number of crypto-draining attacks recently. Per Chainalysis, one online community devoted to a Solana wallet drainer kit had over 6,000 members as of January. The most successful kits can target assets in various ways.

Blowfish has implemented automatic defenses against the newly identified drainers and is monitoring the blockchain for further exploits. Users should be vigilant about only approving transactions from trusted sources on Solana and other chains vulnerable to bit-flip attacks.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: dAppHackSolana
Tweet1ShareShare
Matoy

Matoy

If Matoy is not busy looking at the latest Web3 news, he's always in the kitchen cooking delicious meals for his family. He's also a competitive fighting game player and a car enthusiast

DON'T MISS THESE! HOT OFF THE PRESS

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout
CRYPTO

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout

November 22, 2025
Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next
CRYPTO

Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next

November 22, 2025
Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem
CHAINLINK

Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem

November 22, 2025
Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)
CRYPTO

Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)

November 22, 2025
Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength
CARDANO

Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength

November 22, 2025
Solana Slides to Its Lowest Level Since June — Here Is Why the Market Looks Fragile and What Happens If SOL Can’t Break $130
CRYPTO

Solana Slides to Its Lowest Level Since June — Here Is Why the Market Looks Fragile and What Happens If SOL Can’t Break $130

November 22, 2025
Load More

Related News

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout

BONK Gears Up for Its First ETP — Here Is Why Whales and Hype Might Finally Trigger a Breakout

November 22, 2025
Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next

Uniswap Whales Are Capitulating as UNI Crashes — Here Is Why the Market Looks Fragile and Where Price Might Go Next

November 22, 2025
Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem

Injective Taps Chainlink Data Streams — Here Is Why This Integration Could Supercharge Its Entire DeFi Ecosystem

November 22, 2025
Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)

Grayscale’s Sui Trust Lands on OTCQX — Here Is Why GSUI Isn’t an ETP Yet (and What Comes Next)

November 22, 2025
Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength

Cardano Shrugs Off Network Attack With Rapid Recovery — Here Is Why Hoskinson Says the System Proved Its Strength

November 22, 2025
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews