Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Phantom Confirms Security Amid Solana Library Vulnerability

Phantom Confirms Security Amid Solana Library Vulnerability

Assurance of Platform Safety

Kelly Cromley by Kelly Cromley
Dec 4, 2024
in Market News, News
Reading Time: 3 mins read
0
phantom wallet solana blockchain

Phantom, a prominent wallet provider within the Solana blockchain ecosystem, has confirmed that its platform remains unaffected by a recently identified vulnerability in the Solana/web3.js library. The company’s security team assured users that the compromised library versions, specifically 1.95.6 and 1.95.7, have not and will not be utilized within Phantom’s infrastructure. This clarification was provided to reaffirm the safety of users’ wallets and their associated data.

The vulnerability, brought to light by Solana developer Trent Sol, highlighted the risks posed by these specific versions of the library. These versions were found to contain code capable of enabling secret-stealer attacks, which could potentially expose private keys used for securing wallets. Users and developers relying on the affected versions were advised to upgrade to version 1.95.8 to mitigate these risks. Older versions, such as 1.95.5, have been deemed secure.

Proactive Responses Across the Ecosystem

The Solana ecosystem has shown swift responsiveness in addressing the vulnerability. Several key projects, including Drift, Phantom, and Solflare, have communicated their security status to their respective user bases. These projects either avoided using the compromised library versions or implemented robust security measures to ensure protection against such threats. Developers across the ecosystem have been urged to review their dependencies and update their libraries as a precautionary measure to safeguard funds and sensitive information.

anyone using @solana/web3.js, versions 1.95.6 and 1.95.7 are compromised with a secret stealer leaking private keys. if you or your product are using these versions, upgrade to 1.95.8 (1.95.5 is unaffected)

if you run a service that can blacklist addresses, do your thing with…

— trent.sol (@trentdotsol) December 3, 2024


Escalating Security Challenges

The revelation of the vulnerability underscores the broader security challenges faced by blockchain networks. Forensic analysis of the compromised library versions revealed the presence of embedded malicious commands designed to extract private keys and transmit them to an unauthorized wallet address. This backdoor, which was engineered to exploit vulnerabilities at a sophisticated level, was highlighted by security experts such as Christophe Tafani-Dereeper from Datadog.

Phantom is not impacted by this vulnerability.

Our Security Team confirms that we have never used the exploited versions of @solana/web3.js https://t.co/9wHZ4cnwa1

— Phantom (@phantom) December 3, 2024


Such incidents are not isolated occurrences. Earlier this year, the Python Package Index (PyPI) was the target of a similar attack involving a malicious package called “solana-py.” This package was disguised as a legitimate Solana Python API but was used to harvest wallet keys and send them to an attacker-controlled server. The deceptive naming of the package misled developers, resulting in over 1,100 downloads before the malicious package was identified and removed.

Vigilance and Security Upgrades

The Solana community’s rapid response to these threats emphasizes the importance of vigilance in the blockchain space. Developers are increasingly called upon to ensure the integrity of their software by carefully examining dependencies and implementing timely updates. As blockchain ecosystems grow, so does the sophistication of potential attacks, making robust security frameworks and proactive monitoring essential for maintaining trust and safety.

Phantom’s assurance of security serves as a reassuring example of how timely communication and stringent safeguards can protect users in the face of emerging vulnerabilities. For developers and users alike, the incident underscores the critical need to prioritize security as blockchain technology continues to evolve.

Previous Post

Empowering Japan’s Creator Economy with Web3 Innovation

Next Post

OKX and DeAgentAI Launch $50,000 Airdrop Campaign

Related Posts

tunisia

Tunisia Microfinance Giant Rolls Out Blockchain Loyalty Program

by Kelly Cromley
May 4, 2026
0

Enda Tamweel, recognized as Tunisia’s largest microfinance institution, has introduced a blockchain-based loyalty initiative built on the Hedera network. The...

United Arab Emirates (UAE)

UAE Free Zone Unveils Blockchain Business Identity System

by Kelly Cromley
May 4, 2026
0

Innovation City, an AI-focused free zone in Ras Al Khaimah, has introduced what it described as the world’s first blockchain-based...

v systems

Malaysia Launches First Tokenized Sukuk Pilot Program

by Kelly Cromley
May 4, 2026
0

V Systems Malaysia reported that it had been appointed by Khazanah Nasional to support the country’s inaugural tokenized sukuk pilot...

arxia

Arxia Achieves Offline Blockchain Transaction via LoRa

by Kelly Cromley
May 4, 2026
0

Arxia, an offline-first Layer 1 blockchain developed in Rust, has successfully completed its first fully end-to-end transaction transmitted entirely without...

lava network

Lava Network Partners Bitcore to Scale Digital Finance

by Kelly Cromley
May 4, 2026
0

Lava Network, a decentralized Remote Procedure Call routing protocol designed to deliver fast and secure data access for blockchain applications,...

cycol gallery

Cycol Gallery Blends Solana Blockchain With NYC Art Scene

by Kelly Cromley
May 4, 2026
0

A new contemporary art destination in New York City’s Lower East Side is drawing attention for combining traditional gallery experiences...

Next Post
OKX and DeAgentAI partner for Airdrop Campaign

OKX and DeAgentAI Launch $50,000 Airdrop Campaign

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

tunisia
Market News

Tunisia Microfinance Giant Rolls Out Blockchain Loyalty Program

by Kelly Cromley
May 4, 2026
United Arab Emirates (UAE)
Market News

UAE Free Zone Unveils Blockchain Business Identity System

by Kelly Cromley
May 4, 2026
v systems
Market News

Malaysia Launches First Tokenized Sukuk Pilot Program

by Kelly Cromley
May 4, 2026
arxia
Market News

Arxia Achieves Offline Blockchain Transaction via LoRa

by Kelly Cromley
May 4, 2026
lava network
Bitcoin News

Lava Network Partners Bitcore to Scale Digital Finance

by Kelly Cromley
May 4, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.