CertiK: Discovered a critical vulnerability in Solana Phone that allows user assets to be stolen within tens of seconds
CertiK has discovered a critical bootloader vulnerability in Solana Phone. CertiK's testing experts were able to jailbreak the phone in just one minute and "clean out" all of its assets with just a few steps.
The vulnerability stems from an insecure "bootloader unlock" feature. In addition to stealing user assets, it also exposes all personal data stored on the device. Over 2,100 devices have been at serious risk since early April. Given the complexity of the vulnerability and the need for physical access, CertiK has informed Solana of the vulnerability and publicly released this vulnerability warning to protect Web3 users and encourage them to take effective measures to protect their asset security.
CertiK released a video analyzing the details of the vulnerability on November 15. They emphasized that the vulnerability is not limited to Solana Phone and recommended that relevant projects and developers take immediate action to strengthen bootloader protection.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Can Bitcoin’s Momentum Endure as Long-Term Investors Offload?
Navigating the Uncertainty: Key Factors That May Impact Bitcoin's Future Price Amidst Potential Sell-Off by Long-Term Holders
Is Bitcoin’s Supremacy a Threat or an Opportunity for Altcoins?
Unraveling altcoins' downtrend as Bitcoin tightens grip on market: A Detailed Glimpse into the Altcoin Season Index's Recent Declines
Wall Street CEOs are in Action! Cryptocurrency Plans Emerge One by One
With Donald Trump taking office, Wall Street CEOs have begun to announce their cryptocurrency plans one by one.
Another US State Takes Steps to Create a Bitcoin Strategic Reserve
A US state has taken a new step towards creating a Bitcoin Strategic Reserve. Here are the details.