NFTs

Solana’s Saga Phone is Vulnerable to Critical Exploit, Certik Says

1 Mins read

The exploit could “compromise the most sensitive data stored on the phone, including cryptocurrency private keys.”

Solana’s phone is vulnerable to an attack that can put any digital assets stored on it “at extreme risk,” according to an emailed statement by blockchain security firm Certik.

The vulnerability allows an attacker with physical access to a phone to load custom firmware containing a root backdoor, Certik said, adding that the exploit could “compromise the most sensitive data stored on the phone, including cryptocurrency private keys.”

Solana’s cel phone, which launched in April, is an Android device that was marketed as being “purpose-built for crypto.”

Solana Foundation didn’t immediately reply to a request for comment sent to its press email.

The exploit exposes any plaintext data stored on the device, including private keys.

Two key points of failure exist, according to Certik. First, the phone’s wallet depends only on the device’s operating system for security, and second, its “bootloader unlock” feature, which lets attackers install custom firmware. A hidden root backdoor allows the phone to operate as usual while being compromised.

The wallet app featured here is particularly insecure, falling into the S0 security level, which stores private keys and other sensitive information in plaintext, Certik said.

the-defiant
Solana Phone Risks


Source link

Related posts
NFTs

Our Most Read Stories This Week: Bitcoin Hodlers, Vitalik's Techno Optimism, BTC Miner

1 Mins read
The Defiant’s most read stories for the week of Nov. 27. Source link
NFTs

"EmoteBot" NFT Series by SurR.Ai: Bridging Digital Artistry and Emotional Education.

4 Mins read
SurR.Ai’s “EmoteBot” NFT series is not just an artistic marvel in the digital realm, but also a pioneering venture that seamlessly merges…
NFTs

Pudgy Penguins ATH 🐧 - by William M. Peaster

1 Mins read
Metaversal is a Bankless newsletter for weekly level-ups on NFTs, virtual worlds, & beyond Dear Bankless Nation, While the past two years…

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *