Solana’s investigation into the recent wallet-draining incident has narrowed the focus to the Slope mobile wallet app. In a public update, the Solana Status team said that, after work by developers, ecosystem participants, and security auditors, the affected addresses appeared to have been created, imported, or used at some point in Slope mobile wallet applications. At the same time, the team stressed that there is no evidence that the Solana protocol or its cryptography was compromised.
Investigation shifts attention to the wallet layer
Over the 48 hours following the attack, Solana teams were dealing with a breach that compromised thousands of wallets. Solana Labs co-founder and CEO Anatoly Yakovenko had initially suggested the exploit might be tied to a supply-chain style issue, noting that most reports involved Slope users, with a smaller number coming from Phantom users. As the investigation progressed, the evidence increasingly pointed to Slope’s mobile application environment.
According to Solana Status, the precise mechanism remains under investigation, but current findings suggest that private key information may have been inadvertently transmitted to an application monitoring service. If confirmed, that would place the root cause in wallet-side handling of sensitive data rather than in the base-layer security of the Solana network. The update also said that hardware wallets used with Slope remain secure.
Slope acknowledges compromise and urges migration
Slope Finance later issued its own statement, confirming that a group of Slope wallets had been compromised. The company said it had several working hypotheses about the nature of the breach but no firm conclusion yet. It also noted that some wallets belonging to staff and founders were drained, underscoring that the impact extended inside the organization as well.
The wallet team advised users to create a new wallet with a new and unique seed phrase and move all assets immediately. For users relying on hardware wallets, Slope said their keys had not been exposed.
More than 9,200 addresses affected
Data cited from Dune Analytics suggests the scope of the breach was larger than early reports indicated. The dashboard showed that 9,223 unique addresses were impacted, with total losses reaching $4,088,121. Most of the stolen assets reportedly consisted of SOL and USDC issued on Solana.
Those figures highlight both the breadth of the exploit and the pressure it placed on user trust across the ecosystem. Because the case touches private key storage, mobile wallet architecture, and logging infrastructure, it has quickly become a major security incident for the broader Solana community.
Security researchers point to plaintext seed logging
Further scrutiny from security researchers intensified concerns around Slope’s internal handling of seed phrases. Reports cited in the investigation said mnemonic seed phrases sent to Slope’s server may have been logged in readable plaintext. The allegation is that the wallet team stored mnemonics in debugging logs through a centralized Sentry server.
Security firm Ottersec said that if this setup was in place, then anyone with access to Sentry could potentially access users’ private keys. Ottersec also noted that the Slope team had been helpful in sharing data related to the hack. While the full technical sequence behind the exploit has yet to be disclosed, the investigation so far indicates that the core failure was likely within the wallet application stack, not the Solana protocol itself.

