Subscribe
Logo
Logo
  • Topics Icon Topics
    • AI Icon AI
    • Banking Icon Banking
    • Blockchain/DeFi Icon Blockchain/DeFi
    • Embedded Finance Icon Embedded Finance
    • Fraud/Identity Icon Fraud/Identity
    • Investing Icon Investing
    • Lending Icon Lending
    • Payments Icon Payments
    • Regulation Icon Regulation
    • Startups Icon Startups
  • Podcasts Icon Podcasts
  • Products Icon Products
    • Webinars Icon Webinars
    • White Papers Icon White Papers
  • TechWire Icon TechWire
  • Search
  • Subscribe
Reading
Solana, Nomos exploits show DeFi disruption carries volatility baggage
ShareTweet
solana network logo
Home
Crypto
Solana, Nomos exploits show DeFi disruption carries volatility baggage

Solana, Nomos exploits show DeFi disruption carries volatility baggage

Kevin Travers·
Fintech
·Aug. 16, 2022·6 min read

Solana fell from a proof-of-stake leader to an unstable, frequently offline chain that has been the target of high-stakes, high-profile hacks.

On Aug. 2, an exploit related to the chain exposed 9,233 wallets to a hack that sucked in $4 million of value from users‘ fingertips.

Two days later, on Aug. 4, the decentralized Solana foundation blamed the outbreak on a security flaw within the Slope browser wallet, a popular Solana solution similar to MetaMask purpose-built for the Web3 community. Every exposed account had either used or had a connection to Slope.

Slope then released their report, admitting they recognized a security breach but claimed no responsibility, stating there was no evidence tying the fault to the loss of Solana funds.

 Dune Analytics for Solana hacked article
As these carefully calculated tables from Dune Analytics illustrate, the hack was widespread.

The Slope team said that a third-party app was saving wallet seed phrases and sensitive data “in cases where the apps generated an error event.”

According to Solana, these seed phrases, copied over from Phantom wallet or created within Slope, were used to access users’ funds over four hours.

Solana stated that neither block creation nor any other aspect of the chain was affected, aside from the drained custodial wallets.

The bad news came after a complete chain shut down in June, followed by a programmer spoofing the entire chain’s total value locked (TVL).

What do industry experts think?

Web3 adoption appears inevitable to industry observers, but each passing block brings news of shuttered exchanges, hacks, and deceit.

Nikos Andrikogiannopoulos, CEO of crypto chain tracking firm Metrika, said the multi-chain world’s fast pace of software upgrades would inevitably introduce more vulnerabilities, so it is only natural for exploits to pop up.

Nikos Andrikogiannopoulos, CEO of Metrik headshot for Solana hacked article
Nikos Andrikogiannopoulos, CEO of Metrika

“Effective monitoring infrastructure in the hands of the community acts as a powerful deterrent to bad actors,” he said. “Similar to weather alerts that get communities mobilized, evacuate threatened areas, and activate volunteer rescue teams, blockchain communities need processes and tools to deal with emergencies.”

Daniel Keller, Co-Founder of Web3 cloud infrastructure firm Flux, concurred, saying that disruption is volatile.

“Most of the developers in the blockchain space are learning on the fly, as they come from conventional technology stacks and are retrofitting their skills,” he said.

For decentralization to take over, education will have to become a driving force for better and more secure programming.

Tech is not born

“Technology is not born but instead developed, and as adoption grows, you will see a robust push from leadership driven by the institutional demands for their client base, he said.

“DeFi needs to feel like legacy finance but function like a decentralized network, and for this to happen, we need to be good stewards of speed and security best practices.” 

 for Solana hacked article
Daniel Keller, Co-Founder of Web3 cloud infrastructure firm Flux

They already doubled the total value locked of the network by spoofing numbers, CoinDesk investigators allege. CoinDesk reported that an unpublished blog post allegedly drafted by Saber stablecoin creator Ian Macalinao amounted to a confession that $7 of the $10 billion TVL in Solana was faked by double-counting assets.

Macalinao has not responded to CoinDesk regarding the allegations at the time of their publishing of the investigative report. Fintech Nexus News has also requested a comment from Solana, with no response as of this article’s original publishing Tuesday.

The Nomad hack and cross-chain vulnerability

The hack came a day after a $400-million attack hit the cross-chain coin transfer protocol Nomos bridge.

A crypto bridge connects currencies with an exchange rate. A bridge is either a custodial or decentralized mechanism that takes input cryptocurrencies and outputs other “wrapped” cryptocurrencies. For example, send Nomos bitcoin to “change” for eth, and the protocol would output wrapped bitcoin on the ethereum chain.

Bridges have historically been the target of hackers.

Andrew Morfill, Chief Information Security Officer at coin custodian Komainu, said looters pillage until security can stop them.

“As the industry matures, we will continue to see hacks. From early indications with Nomad, it’s clear that opportunistic looters drove it. Still, nation-state threat actors have targeted cross-chain bridges in the past with meticulous planning and precise execution,” Morfill said. “The drivers are different, but the outcomes, inevitably, are the same…loss of assets.” 

Andrew Morfill headshot
Andrew Morfill, the Chief Information Security Officer at coin custodian Komainu,

Andrikogiannopoulos said that cross-chain is complicated, and with every update comes more bugs to exploit. He explained that the bug the Nomos hackers used was a relatively simple one to understand.

“In the case of Nomad, a bug in the software update allowed a type of transaction that normally should be allowed to only the owners of the funds,” he said. “This bug allowed anyone who wanted to copy-paste the transaction type, change the recipient’s address, and drain the funds.” 

Keller said most of DeFi still relies on a centralized infrastructure.

“Blockchain was created to do one thing, allow movement without a trusted third party. Most of the current DeFi models use a hybrid of centralized and decentralized technology, so there is an increased risk of exploits and malicious third-party actors,” he said.

“Attention needs to be given to security and not just the speed of development as we push DeFi products to the masses.”

What can the industry do to prepare for the next breach?

While hacks are not new, even for Solana, they have amounted to the most significant losses of funds in cryptocurrency, Morfill said.

“In terms of prevention, an industry set of standard smart contract templates known to be secure, smart contract auditing, and secure software development lifecycles would be steps in the right direction,” he said.

Keller said most of the DeFi experts come from traditional finance, and when they build, they focus on speed, Flash Boys style. Of course, he recommended builders flock toward “more secure” infrastructure, like his firm Flux offers.

“Most decentralized finance makeup is refugees from conventional finance, focusing on building a legacy-based system on DeFi,” he said. “When these leaders, developers, and teams focus on iteration, they look at the mechanics and development for speed and quick access; security tends to be an afterthought.”

Fraud checks come after

Andrikogiannopoulos said, unfortunately, a lot of fraud detection comes after the breach when the industry needs a coordinated response at the time of the attack. Like an immune system response, analytics and action need to happen immediately or even before the launch of the attack.

“Many of these exploits start with small experiments, often in TestNet, and later get fully deployed on MainNet. Real-time detection can raise alerts on suspicious activity before these exploits get “into production,” he said.

For example, in the Nomos hack, a transaction with an empty or zero hash executing on the chain should have raised immediate red flags and launched an automated quarantine system. Today, he said that these fixes are ad hoc and community-based when they should be industry automatic and enforced.

“After an exploit goes live, the entire community should be alerted in real-time and quickly and allow for quick community response, like freezing of the exploited funds, coordinating with validators to pause network activity while a patch is prepared,” he said. “There needs to be more tooling and infrastructure in this direction to empower the entire community with a standardized response to emergencies.”

Related:

  • Solana announces Web3 Phone
  • Digital Nomads Find a Growing Ecosystem to fit their Needs
  • UPDATED: Crypto.com confirms hackers stole more than $34 million
  • Fluid Attacks’ Continuous Hacking combines automation, ethical hacking
  • Binance Exchange was Victim of Well Orchestrated Hack
  • Kevin Travers
    Kevin Travers

    Intensely energetic news reporter asking questions covering the collision between Silicon Valley, Wall Street, and everywhere in-between. Studied history at the University of Delaware, learned to write at the Review, and debanked.

    View all posts

Tags
CryptocurrencyNomosSolana
Related

Beware of the crypto/blockchain patent troll

'; Skip to main contentSkip to toolbar About WordPress News 22 updates available 00 Comments in moderation New Blog2Social Perfmatters Forum Dashboard WPForms Howdy, John K. White 0 Log Out Add New Post Save draft Preview Publish Global newsletter: Crypto going to heck in a handbasket We could have devoted this entire newsletter to the crypto crackdown, but that would have been needlessly punitive for all of us. Truth is, we do need to focus most of our attention on World War Web3 (I mean, close enough for alliteration's sake). If we're going to do so, why not feature arguably the best opinion writer in the space: Matt Levine? His take features this subhead: "Also Flo Rida at private equity parties," so you know it will be a fun ride. We've clearly shifted to the farce department as Gary Gensler doubles down on his dimwitted denouement (alliteration is my ear candy). Seeing as Binance US is about to freeze its assets off, it's a prime pun playground for pundits. OK, that's the last one. Featured Share this article USA The SEC Comes for Crypto By Matt Levine Also, Flo Rida at private equity parties. ? From Fintech Nexus Share this article USA Coinbase case: Is clarity from SEC close? By Isabelle Castro Margaroli The SEC's filing against Coinbase was expected but might be the beginning of the end to their years of crypto regulation avoidance. ? Share this article LatAm How LatAm fintechs are diversifying their businesses to tackle challenging times By Jorge C. Carrasco Fintechs are diversifying to survive, adding solutions to monetize their customer base and reduce dependence on riskier lines of business. ? Share this article Fintech Blueprint Long Take: Revolut's $100MM opportunity cost and faltering profitability without a UK banking license By Michiel Milanovic Consumer-led financial technology emerged in full in the wake of the 2008 financial crisis. In the United States, personal financial management like Mint and investment platforms like Betterment came first. In Europe, customers were particularly dissatisfied with their banking experience, leading to the rise of neobanks. ? Also making news USA: Crypto crackdown: Coinbase and Binance lawsuits shake markets The S.E.C.’s actions indicate a push to require crypto businesses offering securities to follow the same rules as traditional stock and bond exchanges. USA: CFPB warns banks that poorly deployed chatbots could harm consumers The Consumer Financial Protection Bureau issued a warning to financial institutions about adopting technologies such as generative chatbots that may provide inaccurate information to consumers. USA: Lawmakers try again to curb Visa, Mastercard fees, with broader support Lawmakers plan to re-up proposed legislation that would give merchants the power to process many credit cards over different networks. USA: SEC's Coinbase complaint sets off battle for crypto's future A wide-ranging regulatory complaint goes well beyond what constitutes a security. USA: How Venmo fosters financial responsibility through Teen Account PayPal-owned mobile payment service Venmo is expanding its reach by rolling out new Venmo Teen Accounts that offer financial flexibility to 13 to 17-year-olds but keep parents in charge. Global: Thunes powers global money transfers with $60m in Series C funding Thunes, a global B2B payment infrastructure platform, has closed its Series C funding round of $60m. Founded in 2016, the company aims to tackle the global inefficiencies present in international money transfers. Global: HSBC says rebranded Silicon Valley Bank UK will maintain startup focus while targeting global growth Silicon Valley Bank UK will continue to serve startup businesses from "seed funding to IPO" after its takeover, the CEO of HSBC UK told CNBC. Europe: UK regulators not ready to deal with digital assets like cryptocurrencies – report A cross-party group of MPs has called for another review into developing skills to help the UK crypto industry grow. ? Toggle panel: Blog2Social: Social Media Content Calendar Toggle panel: Yoast SEO Premium SEO Readability Inclusive language Schema Social News Focus keyphraseHelp on choosing the perfect focus keyphrase(Opens in a new browser tab) Google preview Preview as: Mobile resultDesktop result Url preview: Fintech Nexus www.fintechnexus.com› global-newsletter-crypto-going-to-heck-in-a-handbasket SEO title preview: Global newsletter: Crypto going to heck in a handbasket | News Meta description preview: Jun 7, 2023 ? Please provide a meta description by editing the snippet below. If you don’t, Google will try to find a relevant part of your post to show in the search results. SEO title Insert variable Title Page Separator Site title Slug global-newsletter-crypto-going-to-heck-in-a-handbasket Meta description Insert variable Premium SEO analysisEnter a focus keyphrase to calculate the SEO score Add related keyphrase Internal linking suggestions Advanced Insights Toggle panel: Zeen Subtitle Toggle panel: Let's Live Blog Options Event Schema Enable Live Blog Toggle panel: Zeen Options Hero Layout Header Overrides Sponsored Post Listicle Misc. Media Formats Hero Design Bottom Divider Shape Secondary Hero UPLOAD Hero Image Override UPLOAD Toggle panel: Top 10 Visit count: 0 Enter a number above to update the visit count. Leaving the above box blank will set the count to zero Disable Popular Posts display: If this is checked, then Top 10 will not display the popular posts widgets when viewing this post. Exclude this post from the popular posts list: If this is checked, then this post will be excluded from the popular posts list. Location of thumbnail: Enter the full URL to the image (JPG, PNG or GIF) you'd like to use. This image will be used for the post. It will be resized to the thumbnail size set under Top 10 Settings » Thumbnail options. The URL above is saved in the meta field:post-image Post Block Summary Visibility Public Publish Immediately URL www.fintechnexus.com/global-newsletter-crypto-going-to-heck-in-a-handbasket/ Stick to the top of the blog Pending review POST FORMAT Standard Post Status Draft Move to trash PublishPress Future Enable Post Expiration Yoast SEO Readability analysis: Needs improvement Premium SEO analysis: Needs improvement Inclusive language: Good Improve your post with Yoast SEO Categories SEARCH CATEGORIES Africa Announcements Asia/Pac Blog CEO Roundtables Crypto Digital Banking Editorial Cartoons Europe Finance Fintech Fintech Nexus USA 2022 Fintech Nexus USA 2023 Fintech One-on-One Podcast Fundraising Guest Post Home LatAm Lending Mergers & Acquisitions Middle East News News Roundup NFTs North America Online Lending Opinion Payments Peer to Peer Lending PitchIt Fintech Startups Podcast Podcasts Fintech Blueprint Podcast Fintech Coffee Break Podcast Fintech Nexus Podcast Real Estate Regulation Sponsored USA Add New Category Select the primary category News Roundup Tags ADD NEW TAG Separate with commas or the Enter key. MOST USED lisdigital bankingUSALending ClubUKProsperBlockchainfintechChinapayments Featured image Set featured image Excerpt WRITE AN EXCERPT (OPTIONAL) Learn more about manual excerpts(opens in a new tab) Discussion Allow comments Allow pingbacks & trackbacks Toggle panel: Blog2Social: Autoposter Custom Sharing & Scheduling Info Customize & Schedule Social Media Posts The Autoposter is activated Info Shared: 0 times Last shared: --- Advanced settings Toggle panel: Authors Fintech Nexus Staff Disable post author box display? Toggle panel: Checklist Featured image * Featured image 1280 x 960 * Confirm byline * Add secondary image/headshot * Between 1 and 5 categories * Between 2 and 7 tags Between 75 and 300 characters in excerpt Zeen subtitle filled in * Double-check proper names * Re-verify source quotes * Double-check numbers & dates * Run Grammarly * Add subheads every 300 words Maximize SEO score with Yoast * Meta description * Embed one internal link * External link to 1st mention of companies * Alt text for all images (*) Required Toggle panel: Metadata Open publish panel NotificationsDraft saved. Close dialog Featured image Upload filesMedia Library Expand Details Filter mediaFilter by type Images Filter by date All dates Smush: All images Search Media list Showing 81 of 15167 media items Load more ATTACHMENT DETAILS hell-in-handbasket-wP.jpg June 7, 2023 1 MB 1280 by 960 pixels Edit Image Delete permanently Alt Text Learn how to describe the purpose of the image(opens in a new tab). Leave empty if the image is purely decorative.Title Asian woman dress black as Grim Reaper of death and point the finger at you in Halloween festival. Halloween concept. Caption Asian woman dress black as Grim Reaper of death and point the finger at you in Halloween festival. Halloween concept. Description File URL: https://www.fintechnexus.com/wp-content/uploads/2023/06/hell-in-handbasket-wP.jpg Copy URL to clipboard SmushFile processing is in progress. Selected media actionsSet featured image

Global newsletter: Crypto going to heck in a handbasket

Argentina likely to regulate crypto in 2023

LatAm crypto firms to face tough 2023, focus on rebuilding trust

Popular Posts

Today:

  • Ahead of AIOutsmart Pricing Objections Before They Arise with AI Jul. 1, 2025
  • Revised-AI-InvoiceAI Faces Skepticism. Startups Say: OK, Pay When it Works Jun. 25, 2025
  • Stylizedhouse-with-EKGFintech x the One Big Beautiful Bill Jun. 26, 2025
  • Globe-money-symbolsOPINION: Why Brazil and India are leading the global digital shift through payment innovation Jun. 24, 2025
  • Paraform Founders, Jeffrey Li and John KimFunded: Paraform raises $20M to put top recruiters, not AI, in the driver’s seat Jun. 27, 2025
  • GreenliteAI-Alex-WillGreenlite AI is on a mission to revolutionize banking compliance Jun. 10, 2025
  • Email-AI-pieceAvatar CEOs Have Entered the Meeting Jun. 18, 2025
  • Current stablecoin adoptionWhy Banks (and Fintechs) Need to Embrace Stablecoins Today Jun. 12, 2025
  • TechNexus The AI IssueSteal Like an AI? Defining Fair Use & Creativity Jun. 25, 2025
  • PayabliFunded: Payments infrastructure co Payabli lands $28M Series B to AI-ify Jun. 20, 2025

This month:

  • WP UmbrellaTo Bank or Not to Bank: The ILC Question Jun. 5, 2025
  • DanMurphy-FN-headshotCFPB’s Next Open Banking Battle Begins Jun. 3, 2025
  • GreenliteAI-Alex-WillGreenlite AI is on a mission to revolutionize banking compliance Jun. 10, 2025
  • Current stablecoin adoptionWhy Banks (and Fintechs) Need to Embrace Stablecoins Today Jun. 12, 2025
  • ai-work-nexusWalkMe Vets Declare War on SaaS Bloat with $10M Seed for Autonomous Agents Jun. 10, 2025
  • Ben Hemani, Founding Partner at Bison VenturesThe Risk and Reward of Betting Big on AI’s Next Frontier Jun. 4, 2025
  • Jon StonaTips from Airwallex x McLaren on Making the Best of a Fintech Sponsorship  Jun. 18, 2025
  • Ironclad State of AI ReportThe Economics of AI Trust Jun. 11, 2025
  • Email-AI-pieceAvatar CEOs Have Entered the Meeting Jun. 18, 2025
  • TechNexus The AI IssueMeeker’s AI Bombshell + The VC Betting on AI Reshaping The Physical World  Jun. 4, 2025

  • About
  • Contact
  • Disclaimer
  • Privacy Policy
  • Terms
Subscribe
Copyright © 2025 Fintech Nexus
  • Topics
    • AI
    • Banking
    • Blockchain/DeFi
    • Embedded Finance
    • Fraud/Identity
    • Investing
    • Lending
    • Payments
    • Regulation
    • Startups
  • Podcasts
  • Products
    • Webinars
    • White Papers
  • TechWire
  • Contact Us
Start typing to see results or hit ESC to close
lis digital banking USA Lending Club UK
See all results