Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Phantom Confirms Security Amid Solana Library Vulnerability

Phantom Confirms Security Amid Solana Library Vulnerability

Assurance of Platform Safety

Kelly Cromley by Kelly Cromley
Dec 4, 2024
in Market News, News
Reading Time: 3 mins read
0
phantom wallet solana blockchain

Phantom, a prominent wallet provider within the Solana blockchain ecosystem, has confirmed that its platform remains unaffected by a recently identified vulnerability in the Solana/web3.js library. The company’s security team assured users that the compromised library versions, specifically 1.95.6 and 1.95.7, have not and will not be utilized within Phantom’s infrastructure. This clarification was provided to reaffirm the safety of users’ wallets and their associated data.

The vulnerability, brought to light by Solana developer Trent Sol, highlighted the risks posed by these specific versions of the library. These versions were found to contain code capable of enabling secret-stealer attacks, which could potentially expose private keys used for securing wallets. Users and developers relying on the affected versions were advised to upgrade to version 1.95.8 to mitigate these risks. Older versions, such as 1.95.5, have been deemed secure.

Proactive Responses Across the Ecosystem

The Solana ecosystem has shown swift responsiveness in addressing the vulnerability. Several key projects, including Drift, Phantom, and Solflare, have communicated their security status to their respective user bases. These projects either avoided using the compromised library versions or implemented robust security measures to ensure protection against such threats. Developers across the ecosystem have been urged to review their dependencies and update their libraries as a precautionary measure to safeguard funds and sensitive information.

anyone using @solana/web3.js, versions 1.95.6 and 1.95.7 are compromised with a secret stealer leaking private keys. if you or your product are using these versions, upgrade to 1.95.8 (1.95.5 is unaffected)

if you run a service that can blacklist addresses, do your thing with…

— trent.sol (@trentdotsol) December 3, 2024


Escalating Security Challenges

The revelation of the vulnerability underscores the broader security challenges faced by blockchain networks. Forensic analysis of the compromised library versions revealed the presence of embedded malicious commands designed to extract private keys and transmit them to an unauthorized wallet address. This backdoor, which was engineered to exploit vulnerabilities at a sophisticated level, was highlighted by security experts such as Christophe Tafani-Dereeper from Datadog.

Phantom is not impacted by this vulnerability.

Our Security Team confirms that we have never used the exploited versions of @solana/web3.js https://t.co/9wHZ4cnwa1

— Phantom (@phantom) December 3, 2024


Such incidents are not isolated occurrences. Earlier this year, the Python Package Index (PyPI) was the target of a similar attack involving a malicious package called “solana-py.” This package was disguised as a legitimate Solana Python API but was used to harvest wallet keys and send them to an attacker-controlled server. The deceptive naming of the package misled developers, resulting in over 1,100 downloads before the malicious package was identified and removed.

Vigilance and Security Upgrades

The Solana community’s rapid response to these threats emphasizes the importance of vigilance in the blockchain space. Developers are increasingly called upon to ensure the integrity of their software by carefully examining dependencies and implementing timely updates. As blockchain ecosystems grow, so does the sophistication of potential attacks, making robust security frameworks and proactive monitoring essential for maintaining trust and safety.

Phantom’s assurance of security serves as a reassuring example of how timely communication and stringent safeguards can protect users in the face of emerging vulnerabilities. For developers and users alike, the incident underscores the critical need to prioritize security as blockchain technology continues to evolve.

Previous Post

Empowering Japan’s Creator Economy with Web3 Innovation

Next Post

OKX and DeAgentAI Launch $50,000 Airdrop Campaign

Related Posts

deepsafe partners with arc

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
0

DeepSafe, a decentralized cryptographic verification layer designed for Web3 and artificial intelligence ecosystems, has announced a formal alignment with ARC...

Italy

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025
0

Italy has taken a decisive step toward modernizing its capital markets with the launch of the country’s first minibond fully...

U.S. Securities and Exchange Commission (SEC)

SEC Approves DTCC Pilot to Tokenize U.S. Securities on Blockchains

by Kelly Cromley
Dec 12, 2025
0

The U.S. Securities and Exchange Commission has authorized a three-year pilot program allowing the clearinghouse responsible for nearly all equity...

JP Morgan Chase

JP Morgan Issues Commercial Paper on Solana in Market First

by Kelly Cromley
Dec 12, 2025
0

JP Morgan announced that it has arranged a U.S. commercial paper issuance for Galaxy Digital Holdings LP on the Solana...

make casper d3 global partnership

D3 and InterNetX Move 46 Million Domains Onchain via Solana

by Kelly Cromley
Dec 12, 2025
0

D3 Global and InterNetX announced a major collaboration at Solana Breakpoint 2025 to begin tokenizing more than 46 million internet...

far ai

FAR Labs Unveils Decentralized AI Layer at Dubai Builder Event

by Kelly Cromley
Dec 12, 2025
0

FAR Labs introduced its decentralized AI inference network, FAR AI, at an invite-only gathering in Dubai on December 3, held...

Next Post
OKX and DeAgentAI partner for Airdrop Campaign

OKX and DeAgentAI Launch $50,000 Airdrop Campaign

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

deepsafe partners with arc
Market News

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
Italy
Market News

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025
U.S. Securities and Exchange Commission (SEC)
Market News

SEC Approves DTCC Pilot to Tokenize U.S. Securities on Blockchains

by Kelly Cromley
Dec 12, 2025
JP Morgan Chase
Market News

JP Morgan Issues Commercial Paper on Solana in Market First

by Kelly Cromley
Dec 12, 2025
make casper d3 global partnership
Market News

D3 and InterNetX Move 46 Million Domains Onchain via Solana

by Kelly Cromley
Dec 12, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.