Crypto Wallet Provider Phantom Says Its Systems Were Not Compromised in $4M Hack

After a nearly week-long investigation, its team found no vulnerabilities that could explain the exploit.

AccessTimeIconAug 10, 2022 at 12:22 p.m. UTC
Updated Aug 11, 2022 at 2:43 p.m. UTC
Consensus 2023 Logo
Join the most important conversation in crypto and Web3 taking place in Austin, Texas, April 26-28.

Jamie Crawley is a CoinDesk news reporter based in London.

Consensus 2023 Logo
Join the most important conversation in crypto and Web3 taking place in Austin, Texas, April 26-28.

Solana-based wallet provider Phantom said its systems were not compromised in the exploit where hackers drained around $4 million from over 9,000 wallets.

Phantom tweeted on Tuesday that after a nearly week-long investigation, its team found no vulnerabilities that could explain the exploit. The wallet provider added that it has been independently audited by Halborn Security and OtterSec. The auditing firms have, so far, not found any issues that could explain the incident.

"While some Phantom users were affected, in each case we have reviewed, we found that they had imported their seed phrases/private keys to or from a non-Phantom wallet," Phantom added.

The attack, which started on Aug. 3, affected numerous hot wallet (wallets which stay connected to the internet at all times) providers, such as Slope and TrustWallet, as well as Phantom.

At the time, the Solana network's engineers said that Slope wallets had been compromised, which Slope confirmed but did not say whether the private key storage practices were involved. Phantom added that it had reason to believe "complications related to importing accounts to and from Slope" was the starting point of the attack.

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

CoinDesk - Unknown

Jamie Crawley is a CoinDesk news reporter based in London.


Learn more about Consensus 2023, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.


CoinDesk - Unknown

Jamie Crawley is a CoinDesk news reporter based in London.


Read more about