header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Slow Mist: Traceability Analysis of Solana Public Chain Large-Scale Stealing Events

Read this article in 27 Minutes
The phased investigation shows that the suspected OTC personal wallet address is related to multiple domestic money laundering cases
Original title: "Slow Mist: Analysis of Solana Public Chain Large-Scale Stealing Events (Continued)"
Original Author: Slow Mist Security Team, Slow Mist Technology

< br>

Background Overview


August 3, 2022, Solana Large-scale coin theft occurred on the public chain, and a large number of users were transferred SOL and SPL Token without knowing it. The SlowMist security team immediately intervened in the analysis, and analyzed the Slope wallet application at the invitation of the Slope team. The analysis showed that: the version of the Slope wallet released on or after June 24, 2022 sent private messages to the third-party application monitoring service. Phenomenon of key or mnemonic information.


But from the investigation of the Slope wallet application to the present, it is impossible to clearly prove the root cause of the incident It was the problem of the Slope wallet, so the SlowMist security team began to analyze and collect evidence from the Slope server.


Analysis process


After the incident, all parties focused on investigating the root cause of the incident and the possibility of tracking and saving funds. So the SlowMist security team formulated relevant plans and began to investigate and analyze from the off-chain and on-chain parts.


In the direction of event root investigation, the SlowMist security team focused on the Slope server Analytical forensics. There is a lot of complicated work that needs to be advanced, and more clear evidence is needed to explain the root cause of this large-scale theft.


For the possibility of fund tracking and saving, the SlowMist security team mainly relies on MistTrack ( https://misttrack.io/)’s tracking and analysis capabilities, labeling data capabilities, combined with intelligence capabilities, do our best to identify and track hackers’ on-chain behavior. And also communicated with the Slope team about the possibility of rescue. The Slope team is also trying to communicate with hackers, hoping to encourage hackers to return assets by issuing bug bounties, and jointly maintain the healthy development of the Solana ecosystem.


This article only synchronizes phased investigations with community users , there is still a lot of analysis work in progress, and it is constantly advancing. Not only SlowMist, but also other third-party security teams, and some special forces are also working hard to help with the investigation, hoping that this incident will eventually come to a relatively clear conclusion.


Note: The Sentry service mentioned in this article refers to the Sentry service deployed privately by the Slope team Services, not using the official interfaces and services provided by Sentry.


Some questions


Before analyzing the situation synchronously, let’s answer Some doubts in the analysis process of the previous article:


1. Is Sentry’s service collecting mnemonic words from users’ wallets a common security issue?


Answer: Sentry is mainly used to collect abnormal or error log information that occurs when related application services are running. In the case of configuration errors, it may collect Unexpected data, such as: information such as private keys or mnemonic words, so it is not a universal security problem. Developers must remember not to enable Debug mode in the production environment when using third-party application monitoring services.


2. Phantom uses Sentry, so will the Phantom wallet be affected?


Answer: Although Phantom uses a third-party application monitoring service, the SlowMist security team has not found out that Sentry has uploaded private Key/mnemonic behavior.


3. According to the survey data provided by Solana Foundation, nearly 60% of the stolen users used Phantom wallet, about 30% of addresses use Slope wallet, and the rest of users use Trust Wallet, etc., so what is the reason for these 60% stolen users to be hacked?


Answer: After comparison, it is found that the addresses (including HD addresses) derived from the private key and mnemonic words on the server overlap with the victims’ addresses in 5 ETH addresses and 1388 Solana addresses. According to the current investigation, there is no clear evidence to explain why some other users' wallets were hacked.


4. As a very widely used service, Sentry will be officially encountered by Sentry Invasion? This has led to targeted attacks on the cryptocurrency ecosystem?


Answer: At present, there is no evidence that the official Sentry has been invaded and attacked. The Sentry used by the Slope wallet is an internal service, so it has nothing to do with the official service being invaded Direct relationship.


Off-chain analysis section


< p>

Part of the off-chain SlowMist security team mainly focuses on investigating the possibility of intrusion on off-chain servers and related backgrounds. Risk investigation, server intrusion trace inspection, Sentry (PostgreSQL) database analysis, server mirror analysis, DNS hijacking possibility analysis. The investigation and analysis are as follows:


1. Peripheral server asset risk investigation


After the Slope team knew that the mnemonic phrase and private key information were sent back by the Slope wallet, they immediately shut down the services related to the Slope wallet. Therefore, the services related to the Slope wallet can no longer be directly accessed. The SlowMist security team relies on Internet search engines and other tools to collect information on Slope’s peripheral server assets, including the subdomain names and IPs under the slope.finance domain name for simulated penetration test analysis and investigation. From the possible intrusion risk points on the periphery, no risk points that can be directly invaded have been found through analysis and penetration testing.


2. Server intrusion trace investigation


Mainly conduct internal investigations on third-party application monitoring servers, including server login logs, system historical operation commands, suspicious processes, suspicious network connections, suspicious system scheduled tasks, data deletion and acquisition operations, etc. There are 5 other internal servers A Docker service also conducts the same intrusion trace investigation. The investigation found several suspicious login IPs: 113.*.*.*, 114.*.*.*, 153.*.*.*, these IPs had accessed the background of the third-party application monitoring service before 06.24. Although this happened before the time (06.24) when the private key and seed phrase were returned, it is still suspicious.


3. PostgreSQL database analysis


Because the mnemonic and private key are sent back to the server by the third-party application monitoring service of Slope Wallet, the SlowMist security team also analyzed the possible location of the private key or mnemonic in the server, and found that The private key or mnemonic may be stored in the following locations:


· Sentry's database table


· PostgreSQL's database log


·  In the deleted data of the mirror disk


· In the data file of the Docker runtime


During the analysis process, it was found that the third-party application monitoring service uses a PostgreSQL database, in which the data field of the nodestore_node table It was found that there was private key and mnemonic data collected by a third-party application monitoring service. After analysis and investigation, the following information is obtained:


· The data content of the private key and mnemonic words are recorded in the database of the nodestore_node table for 2022.7.28 - 2022.8.5.


· SlowMist Security Team decrypted and analyzed the data and found that the private key or mnemonic data contained The earliest data was uploaded on June 29, 2022, which means that the data collected by Sentry on June 29 was delayed by one month before being stored in the nodestore_node table of the PostgreSQL database on July 28, 2022, but this part of the delayed data Accounted for less, most of the private key and mnemonic collection time is concentrated in 2022.07.28 - 2022.08.05.


· Further investigation of the database operation log, it was found that before 7.28, there was a record of SQL statement execution failure in the nodestore_node table, because the key Value conflict. After in-depth investigation and communication, it was found that the data was not written due to an error in the Kafka service.


· Because part of the data cannot be recovered temporarily during log recording and data recovery, further data processing is required Therefore, the data that can be completely recovered is firstly decrypted. The number of decrypted addresses is 189 ETH addresses and 4914 Solana addresses, and there are 5073 sets of mnemonic words. The wallet addresses of the hacking event on the chain include 42 ETH addresses and 9231 Solana addresses, after comparison, it is found that the addresses (including HD addresses) derived from the private key and mnemonic phrase on the server intersect with the victims' addresses, including 5 ETH addresses and 1388 Solana addresses. (This does not include a small number of data that need to be repaired before decryption)


· In the database operation log, another An internal test application com.slope.game also had private key and mnemonic data reported in March, and this internal test application has not been released to the public.


4. Server mirror analysis


The SlowMist security team analyzed the image of Sentry's cloud server and recovered the deleted data on the server disk, and found private key and mnemonic information in the recovered data.


5. Possibility analysis of DNS hijacking


< /p>

Through the capabilities of all parties and global intelligence resources, including the query and analysis of DNS resolution data, the SlowMist security team has no clear evidence to prove that the domain name o7e.slope.finance has ever had a DNS hijacking incident.


Phase conclusion of off-chain investigation and analysis:


Based on the investigation and analysis at this stage, no risk point that the peripheral server can be directly invaded has been found; no trace of the server being invaded has been found, but the suspicious IP (113.*. *.*,114.*.*.*,153.*.*.*) Still need to continue investigation; DNS hijacking is less likely; data recovered in database tables, database log files, disk deleted files The private key and mnemonic information were found in .


On-chain analysis

< br>

The on-chain part mainly focuses on risk fund assessment, stolen fund transfer and hacker trace analysis, focusing on the following points :


1. Venture Capital Evaluation


According to the stolen funds of the Solana chain, ETH chain, and BSC chain, the SlowMist security team divides the risk funds into the following two categories:


< b>· Risk Funds: Funds where hackers have address authority.


· Suspected risk funds: funds that hackers may have address authority.


Venture capital assessment based on the following address list (mainly Solana chain, ETH chain):< /p>


· The stolen address mnemonic is mapped to the address of other chain


· The address derived from the stolen address mnemonic through the derivation path


< p>

Exclude the risk capital address list, and conduct suspected risk capital assessment based on the following address list (mainly Solana chain, ETH chain):


· The address of the mnemonic/private key record on the Slope server


·  ;The mnemonic phrase existing on the Slope server is mapped to the address of other chains


· The mnemonic phrase existing on the Slope server Addresses deduced through derivation paths


No large amounts of transferable risk funds and possible existence risky funds.


2. Stolen funds statistics


In order to avoid the impact of some junk coins on stolen funds, we only count the stolen funds of mainstream currencies in the statistical process:


· Solana chains: SOL, USDC, USDT, BTC and ETH.


· ETH Chains: ETH, USDT, USDC and PAXG.


The value of the stolen currency is based on the day of the theft (UTC time August 3 at 00:00 AM) price.


1 SOL = $38.54


1 BTC = $22,846.51


1 ETH = $1,618.87


1 PAXG = $1,759.64


1 BNB = $298.36



The address (including HD address) derived from the decrypted private key and mnemonic on the Slope server is the same as Analyze the victims’ addresses on the chain. There are 5 ETH addresses and 1388 Solana addresses. The stolen funds statistics for these overlapping addresses are as follows. The stolen funds account for 10% of the total stolen funds. 31.42%.


< /p>


3. Fund transfer analysis 


Solana chain:


The funds have not been further transferred as of the time of publication.


ETH Chain:


· 21,801 USDT was transferred to the personal wallet address (according to the behavior characteristics on the chain and MistTrack's tagging ability, this address is suspected of being an OTC transaction address). The SlowMist security team is communicating and cooperating with all parties to trace the identity of the hacker.


·  Most of the remaining funds are converted to ETH and transferred to Tornado.Cash.




BSC Chain:


Funds have not been further transferred by the time of publication.


4. Timeline analysis on the hacker chain


< /p>

According to the behavior of hackers on the chain, the timeline is sorted out as follows:



< /p>

5. Hacker trace analysis Hacker address list is as follows:



The list of suspected hacker addresses is as follows:



First Transfer


The first transfer transactions on the chain of Solana chain hacker wallet 1, 2, 3 and 4 are all transfers of 0.1 SOL from the suspected hacker wallet of Solana chain. According to the analysis of traces on the chain, it is estimated that the suspected hacker wallet on the Solana chain may be the hacker's address, and it is more likely to be the victim's address.


Hackers use tools in the process of money laundering


· TransitSwap


·  Uniswap


· MetaMask Swap


< /p>

Money laundering by hackers


·

· Transfer to the suspected OTC personal wallet address (mentioned above).


·  Transfer to Tornado.Cash.


Relationship between hacker address and trading platform


Direct connection:


· TRON chain, hacker 8 Deposit USDT to Binance on May 5th


Deposit address: TE4bkS2PYqWxijgh5eqEz9A5jLn7HcS6fn


Deposit transaction: b6615bf10b2e619edc9315a08f89732664adc9d385c 980f77caa6e82872fe376< /p>


· TRON chain, hackers withdrew TRX from Binance on August 5


< /p>

Withdrawal transaction: 0e012643a7db1b8c5d1f27447b16e313d4b3f89efaa22b3661188fe399cd2d0e


· ETH chain, hacker withdraws from Binance on August 5 ETH


Withdrawal transaction: 0xd035e009173e968d8f72de783f02655009d6f85ef906121e5b99b496a10283dd


·  ETH chain, hackers withdrew USDC from Binance on August 8 p>· ETH chain, hackers withdrew USDC from Binance on August 10


Withdrawal transaction: 0xc861c40c0e53f7e28a6f78ec9584bfb7722cec51843ddf714b9c10fc0f311806


· TRON chain, hackers withdrew USDT from Binance on August 10


Withdrawal transaction: 10c4186e4d95fb2e4a1a31a18f750a39c0f803d7f5768108d6f219d3c2a02d26


Indirect connection:


· Solana chain suspected hacker wallet withdraws SOL from Binance on January 8


Withdrawal transaction: 668jpJec7hiiuzGDzj4VQKSsMWpSnbzt7BLMGWQmrGvHVQQbNGc3i1g8dCj2F5EAxFT8oDG5xWPAeQUMEMBTjhZs


· Solana chain suspected hacker wallet exists with Solrazr On-chain traces of IDO program interaction


Transaction: 2LxLhL7oAiTyHGrAXCZEJyazQQLM7veaKvqUZL6iPkonL4wPLHcwV66MFX3ERyWvJtdd2wFdKfgKUuT1oAv2XepK


·  Suspected OTC personal wallet address (mentioned above) has deposit and withdrawal relationships with Binance, Kucoin and OKX multiple trading platforms


< img src="https://image.blockbeats.cn/upload/2022-08-17/7f9c6c50d125f9a4a2ba5f45665a7c166621d555.png?x-oss-process=image/quality,q_50/format,webp">


Suspected information connection of OTC personal wallet address< /b>


According to the relevant information obtained by SlowMist, the suspected OTC personal wallet address (TGBrAiVArhs5Cqp2CGMYUpSmkseznv1Ng7) is related to money laundering in multiple domestic cases, including Telephone fraud, USDT theft and TRC20 theft, etc.


Attachment - on-chain analysis data source


· Hacking Solana chain transaction record summary table


< /p>

· Sentry callback problem leads to possible exposed Slope address stolen transaction table


Original link


Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia

举报 Correction/Report
Choose Library
Add Library
Cancel
Finish
Add Library
Visible to myself only
Public
Save
Correction/Report
Submit