On January 7, 2026, OKX Wallet issued a high-risk alert about a new wave of signature phishing attacks on the Solana blockchain. The attack allows scammers to take over a user's account without any visible token transfer, even when wallet simulations show "no balance change." Phantom Wallet has also flagged similar risks.
Silent Takeover: How the Scam Works
Unlike traditional scams that steal seed phrases, this method exploits Solana's "Owner" permission field. Attackers lure victims to fake pages offering "free airdrops," "staking rewards," or "minting whitelists" and prompt them to sign a transaction. The wallet's simulation shows no balance change because no SOL or tokens are moved—yet the transaction contains a hidden instruction that reassigns ownership of the account. Once the user confirms, the hacker becomes the owner, gaining full control over the wallet.
Even if victims still possess their recovery phrase, they cannot reverse the takeover. The attacker can drain funds at any time, leaving the original owner as a mere spectator.
Wallet Providers Respond
OKX Wallet has enhanced its product to detect and flag these malicious instructions. Phantom Wallet has implemented similar risk markings. However, OKX warned that many other mainstream wallets have not yet updated their security protocols to catch this specific technique. To prevent a cross-ecosystem crisis, OKX has sent safety reminders to other digital wallet teams and offered technical support for better detection.
The attack chain works like this: a user clicks a phishing link, sees a seemingly normal transaction request, and a wallet pop-up asks for a signature. Most wallet simulators only check for direct token transfers and miss the hidden instruction. Scammers exploit this blind spot.
Industry Reaction: Solana's Achilles' Heel
Blockchain security firm SlowMist has previously noted that this "ownership modification" attack is one of the most counter-intuitive for users coming from Ethereum. While Ethereum accounts are strictly controlled by private keys, Solana's modular design allows delegation of authority—a feature now being weaponized. Experts estimate that phishing-driven losses in the Solana ecosystem reached approximately $90 million in the first half of 2025. If wallet providers fail to adapt, this new signature method could push losses even higher in 2026.
Solana's speed and flexibility are its strengths, but scammers are exploiting that same flexibility. This is not a bug in Solana; it is an exploit of human habit. Most users are trained to look for balance changes in wallet pop-ups. By crafting transactions that show zero balance change while transferring ownership, hackers have found a massive blind spot. If your wallet does not explicitly tell you that you are assigning owner permission, you are flying blind.

