Slope Wallet hack — August 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | August 3, 2022 |
| Target type | Wallet software or provider |
| Loss | $4,100,000Published estimates range $4,000,000 to $5,000,000Price at time of incident |
| Method | Private key compromiseUsers' BIP39 mnemonic seed phrases were transmitted in plaintext from Slope's iOS and Android wallet apps to a self-hosted Sentry application-monitoring instance Slope operated. Slope attributed this to a toString() method added on 24 June 2022 that defeated Sentry's sensitive-data scrubbing, plus plaintext logging introduced to speed up decryption for an encrypted-messaging feature. The resulting drain transactions were correctly signed with the users' own keys. |
| Chains | Solana |
| Outcome | Unresolved |
What happened
Beginning at 22:37 UTC on 2 August 2022 an attacker emptied thousands of Solana wallets over roughly four to seven hours. The Solana Foundation counted about 9,231 drained wallets and around $4.1 million in assets. Slope's own report put it at 9,229 wallets and roughly $4 million. Elliptic and AnChain told The Block the figure was at least $5 million.
The transactions were properly signed, which pointed at key material rather than a protocol flaw. Solana Labs and the Solana Foundation said no core Solana code was involved. Researchers at Otter Security found that Slope's mobile wallet apps for iOS and Android were transmitting users' mnemonic seed phrases in plaintext to a Sentry application-monitoring instance Slope ran itself, at o7e.slope.finance. Sentry later stated that its own SaaS product and infrastructure were not involved and that the host in question was a self-hosted deployment. Slope's digital-forensics report attributed the exposure to two unrelated mistakes: a toString() method added on 24 June 2022 that defeated Sentry's sensitive-data scrubbing, and plaintext logging introduced to speed up decryption for an encrypted-messaging feature. Because Solana and Ethereum both use BIP39 mnemonics, users who reused a Slope seed phrase in Phantom or Solflare, or on Ethereum, were also exposed. Hardware wallets were unaffected.
The causal link is disputed. Slope said private keys for 6,811 wallets were found on its Sentry database but that only 1,444 of those were among the 9,229 wallets actually drained, and audits by OtterSec and SlowMist found no conclusive evidence tying the Sentry exposure to the drain. Slope shut down the Sentry server on 3 August, pulled its mobile apps on 5 August and told users to abandon the affected addresses.
Sources
- Solana FoundationPrimary · retrieved 2026-08-01
- Slope FinancePrimary · retrieved 2026-08-01
- SentryPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
Official post-mortem: https://slope-finance.medium.com/slope-wallet-sentry-vulnerability-digital-forensics-and-incident-response-report-d7a5904e5a39
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Slope Wallet hack — August 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/slope-wallethttps://itokenly.com/hacks/slope-walletPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.