{"id":194170,"date":"2023-11-15T21:45:00","date_gmt":"2023-11-15T16:15:00","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=194170"},"modified":"2023-11-15T21:45:00","modified_gmt":"2023-11-15T16:15:00","slug":"solanas-saga-phone-is-vulnerable-to-critical-exploit-certik-says-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/solanas-saga-phone-is-vulnerable-to-critical-exploit-certik-says-crypto-news\/","title":{"rendered":"Solana&#8217;s Saga Phone is Vulnerable to Critical Exploit, Certik Says &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<p>The exploit could &#8220;compromise the most sensitive data stored on the phone, including cryptocurrency private keys.&#8221;<\/p>\n<div>\n<p>Solana\u2019s phone is vulnerable to an attack that can put any digital assets stored on it &#8220;at extreme risk,&#8221; according to an emailed statement by blockchain security firm Certik. <\/p>\n<p>The vulnerability allows an attacker with physical access to a phone to load custom firmware containing a root backdoor, Certik said, adding that the exploit could &#8220;compromise the most sensitive data stored on the phone, including cryptocurrency private keys.&#8221;<\/p>\n<p>Solana&#8217;s cel phone, which launched in April, is an Android device that was marketed as being &#8220;purpose-built for crypto.&#8221; <\/p>\n<p>Solana Foundation didn&#8217;t immediately reply to a request for comment sent to its press email.<\/p>\n<p>The exploit exposes any plaintext data stored on the device, including private keys. <\/p>\n<p>Two key points of failure exist, according to Certik. First, the phone&#8217;s wallet depends only on the device\u2019s operating system for security, and second, its &#8220;bootloader unlock&#8221; feature, which lets attackers install custom firmware. A hidden root backdoor allows the phone to operate as usual while being compromised.<\/p>\n<p>The wallet app featured here is particularly insecure, falling into the S0 security level, which stores private keys and other sensitive information in plaintext, Certik said.<\/p>\n<figure><figcaption class=\"text-center text-xs\">Solana Phone Risks<\/figcaption><\/figure>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The exploit could &#8220;compromise the most sensitive data stored on the phone, including cryptocurrency private keys.&#8221; Solana\u2019s phone is vulnerable to an attack that can put any digital assets stored on it &#8220;at extreme risk,&#8221; according to an emailed statement by blockchain security firm Certik. The vulnerability allows an attacker with physical access to a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":194171,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[274,273,272,244,266,271,268,270,269,267],"class_list":["post-194170","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-de-fi","tag-crypto-finance","tag-decentralized-finance","tag-liquidity","tag-metamask","tag-pancake","tag-slippage","tag-sushiswap","tag-tronlink","tag-trust-wallet","tag-uniswap"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/194170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=194170"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/194170\/revisions"}],"predecessor-version":[{"id":194172,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/194170\/revisions\/194172"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/194171"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=194170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=194170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=194170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}