Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Phantom Confirms Security Amid Solana Library Vulnerability

Phantom Confirms Security Amid Solana Library Vulnerability

Assurance of Platform Safety

Kelly Cromley by Kelly Cromley
Dec 4, 2024
in Market News, News
Reading Time: 3 mins read
0
phantom wallet solana blockchain

Phantom, a prominent wallet provider within the Solana blockchain ecosystem, has confirmed that its platform remains unaffected by a recently identified vulnerability in the Solana/web3.js library. The company’s security team assured users that the compromised library versions, specifically 1.95.6 and 1.95.7, have not and will not be utilized within Phantom’s infrastructure. This clarification was provided to reaffirm the safety of users’ wallets and their associated data.

The vulnerability, brought to light by Solana developer Trent Sol, highlighted the risks posed by these specific versions of the library. These versions were found to contain code capable of enabling secret-stealer attacks, which could potentially expose private keys used for securing wallets. Users and developers relying on the affected versions were advised to upgrade to version 1.95.8 to mitigate these risks. Older versions, such as 1.95.5, have been deemed secure.

Proactive Responses Across the Ecosystem

The Solana ecosystem has shown swift responsiveness in addressing the vulnerability. Several key projects, including Drift, Phantom, and Solflare, have communicated their security status to their respective user bases. These projects either avoided using the compromised library versions or implemented robust security measures to ensure protection against such threats. Developers across the ecosystem have been urged to review their dependencies and update their libraries as a precautionary measure to safeguard funds and sensitive information.

anyone using @solana/web3.js, versions 1.95.6 and 1.95.7 are compromised with a secret stealer leaking private keys. if you or your product are using these versions, upgrade to 1.95.8 (1.95.5 is unaffected)

if you run a service that can blacklist addresses, do your thing with…

— trent.sol (@trentdotsol) December 3, 2024


Escalating Security Challenges

The revelation of the vulnerability underscores the broader security challenges faced by blockchain networks. Forensic analysis of the compromised library versions revealed the presence of embedded malicious commands designed to extract private keys and transmit them to an unauthorized wallet address. This backdoor, which was engineered to exploit vulnerabilities at a sophisticated level, was highlighted by security experts such as Christophe Tafani-Dereeper from Datadog.

Phantom is not impacted by this vulnerability.

Our Security Team confirms that we have never used the exploited versions of @solana/web3.js https://t.co/9wHZ4cnwa1

— Phantom (@phantom) December 3, 2024


Such incidents are not isolated occurrences. Earlier this year, the Python Package Index (PyPI) was the target of a similar attack involving a malicious package called “solana-py.” This package was disguised as a legitimate Solana Python API but was used to harvest wallet keys and send them to an attacker-controlled server. The deceptive naming of the package misled developers, resulting in over 1,100 downloads before the malicious package was identified and removed.

Vigilance and Security Upgrades

The Solana community’s rapid response to these threats emphasizes the importance of vigilance in the blockchain space. Developers are increasingly called upon to ensure the integrity of their software by carefully examining dependencies and implementing timely updates. As blockchain ecosystems grow, so does the sophistication of potential attacks, making robust security frameworks and proactive monitoring essential for maintaining trust and safety.

Phantom’s assurance of security serves as a reassuring example of how timely communication and stringent safeguards can protect users in the face of emerging vulnerabilities. For developers and users alike, the incident underscores the critical need to prioritize security as blockchain technology continues to evolve.

Previous Post

Empowering Japan’s Creator Economy with Web3 Innovation

Next Post

OKX and DeAgentAI Launch $50,000 Airdrop Campaign

Related Posts

The Open Network (TON)

Telegram’s Cocoon Aims to Redefine Private, Decentralized AI

by Kelly Cromley
Dec 5, 2025
0

Telegram has introduced Cocoon, a decentralized AI computation network built on the TON blockchain, marking a significant move toward privacy-preserving...

base

Base–Solana Bridge Targets Smoother Crosschain Liquidity

by Kelly Cromley
Dec 5, 2025
0

Base has introduced a Chainlink-secured bridge connecting its Ethereum layer-2 network with the Solana blockchain, marking a notable step toward...

bullfrog power

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025
0

Bullfrog Power has introduced a new initiative aimed at strengthening transparency in environmental reporting by issuing tokenized sustainability certificates on...

titan trading platform

Titan–Zeni Alliance Aims to Elevate AI-Powered Crypto Trading

by Kelly Cromley
Dec 5, 2025
0

Titan Trading Platform has revealed a strategic collaboration with Zeni.io, a provider specializing in data infrastructure tailored for AI agents....

agi open network

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025
0

AGI Open Network (AON), a prominent decentralized ecosystem for building AI agents, has entered a strategic partnership with Infiblue World,...

N3XT

Blockchain-Driven N3XT Bank Promises Instant 24/7 Dollar Payments

by Kelly Cromley
Dec 4, 2025
0

A new player in financial services, N3XT, has formally launched with the goal of reshaping business-to-business payments through blockchain technology....

Next Post
OKX and DeAgentAI partner for Airdrop Campaign

OKX and DeAgentAI Launch $50,000 Airdrop Campaign

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

The Open Network (TON)
Market News

Telegram’s Cocoon Aims to Redefine Private, Decentralized AI

by Kelly Cromley
Dec 5, 2025
base
Market News

Base–Solana Bridge Targets Smoother Crosschain Liquidity

by Kelly Cromley
Dec 5, 2025
bullfrog power
Market News

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025
titan trading platform
Market News

Titan–Zeni Alliance Aims to Elevate AI-Powered Crypto Trading

by Kelly Cromley
Dec 5, 2025
agi open network
Market News

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.