01.03.2024 Views

SHILL Issue 150

Solana ecosystem magazine.

Solana ecosystem magazine.

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

forms, and deceive victims into signing malicious transactions<br />

to steal everything they have. But how successful<br />

are they? The scariest part is how far a single motivated…<br />

Show more<br />

the largest impediments to mass adoption for Solana. The<br />

dynamic it creates makes web3 inhospitable to anyone<br />

other than the truly battle-hardened.<br />

Quote<br />

Almost every person in the space knows somebody who<br />

has been drained, and the reason is obvious: Millions of<br />

scam NFTs are sent out to anyone with a wallet on Solana<br />

— every single day.<br />

Slorg<br />

Imagine if anyone could toss wadded up pieces of paper<br />

into your bank account. And on days when you might be<br />

a bit too tired or uncritical, you open to read one — and<br />

suddenly your life savings is gone. This is the current wallet<br />

experience for many people.<br />

Show more<br />

But why are these drains even possible? This will be easier<br />

to understand with 3 examples: 1. The Bitflip Attack: You<br />

sign a txn, and the bad actor is able to alter a state in<br />

the smart contract(which you approved) from inactive to<br />

active.<br />

Because there is a 2 minute window before transactions<br />

expire, the bad actor can toggle this state on. Then he<br />

sends the transaction to the network with the malicious<br />

smart contract now in an active state.<br />

Not only that — but bad actors are on the ground posting<br />

scams under tweets, and preying on people in Discord.<br />

More recently, they’ve begun forming affiliate groups<br />

where they teach others the skillset for a cut of the profit.<br />

It would not be an overstatement to say that this is one of

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!