A hacker exploited a vulnerability in the Solana JavaScript library, stealing $160,000 in a supply chain attack on December 3.
How It Happened
The incident began when the attacker gained access to an account authorized to publish updates to the solana/web3.js library, a critical tool for Solana-based applications. They injected malicious code, which allowed them to harvest private key data and drain funds from vulnerable users.
Although non-custodial wallets were unaffected, applications relying on private keys processed through the compromised library faced potential risks. Tools like trading bots were likely targets, though platforms such as Trojan, BONKbot, and Photon confirmed they were not impacted.
Anza engineer Trent.sol quickly flagged the issue, urging developers to update to the patched version of the library and blacklist the exploiter’s wallet. This swift action helped prevent additional losses.
Lessons and Response
The exploit highlights the importance of securing both production pipelines and external integrations. Phishing and social engineering attacks often exploit overlooked vulnerabilities, underscoring the need for vigilant security practices.
Anza released an official statement emphasizing that the Solana protocol itself remained secure, with the exploit limited to a specific library. The rapid fix received praise from the Solana community, including Streamflow founder Malisha, who credited Anza’s timely response for mitigating further damage.
This attack stands out in what has otherwise been a quieter year for Solana-related hacks, with fewer losses reported compared to competing blockchain ecosystems in 2024.
Disclaimer: This content does not constitute trading or investment recommendations. It’s essential to conduct your own research before purchasing any cryptocurrency or investing in any services.















