On August 3, 2022, Solana ecosystem investigators were tracing a large-scale drain of internet-connected wallets after users reported unauthorized transfers bearing valid signatures. An early Solana Status count placed the number of affected wallets at 7,767. Elliptic’s update at 5:40 p.m. on August 3 counted 7,947 wallets and more than $5.8 million in stolen assets, including SOL, a small number of non-fungible tokens and more than 300 Solana-based tokens.

The numbers were preliminary snapshots of an active investigation, not a final loss statement. They nevertheless established a significant compromise of users’ signing credentials. Slope Finance confirmed on August 3 that a cohort of its wallets had been compromised and that wallets belonging to some of its staff and founders were also drained.

What investigators knew on August 3

The unauthorized transfers were properly signed. That observation pointed toward exposed private keys or seed phrases—the credentials controlling a wallet—rather than forged transactions accepted through a consensus failure.

Solana Status said the incident did not appear to be a bug in Solana’s core code. Investigators found that affected addresses had at some point been created, imported or used in Slope’s mobile applications. Phantom separately believed its affected users were connected to account imports involving Slope, although the investigation had not established that every reported loss followed the same path.

Slope’s own August 3 statement remained cautious. The company said it had hypotheses but had not firmly confirmed the nature of the breach. It advised users to create wallets with new, unique seed phrases and said hardware-wallet keys had not been compromised. Those statements were contemporaneous claims from an involved vendor, not an independent forensic conclusion.

The careful distinction mattered. Calling the event a “Solana hack” could suggest that the blockchain’s consensus or transaction-processing code had failed. The evidence available on August 3 instead indicated that someone had obtained credentials capable of authorizing ordinary transactions from many user-controlled accounts. Solana was the settlement network on which much of the damage appeared, but the suspected failure boundary was wallet software and its handling of secrets.

Why the incident mattered

Wallet applications occupy a critical position between a blockchain and its users. They generate or import seed phrases, derive signing keys and present transactions for authorization. A flaw at that layer can expose assets across multiple applications if the same seed phrase is reused or imported elsewhere, even when the underlying blockchain continues processing blocks as designed.

That made the incident an institutional test of software supply chains, telemetry practices and incident disclosure. Users could see transfers on-chain, but public transaction visibility did not identify how the attacker acquired the signing material. Investigators still needed application records, software builds and service-provider logs to reconstruct the breach.

The event also demonstrated why wallet counts and dollar-loss estimates require qualification. Addresses are not necessarily unique people, investigators can classify addresses differently, and the dollar value of volatile tokens depends on the prices and timestamp used. Elliptic’s $5.8 million figure was its August 3 on-chain estimate, not an audited victim-compensation total or a market-wide loss calculation.

What remained uncertain

As August 3 ended, the identity and number of attackers, the exact path by which credentials were obtained, the complete set of affected addresses and the recoverable amount were unresolved. Reports that Slope had exposed seed phrases through logging infrastructure were developing and should not have been presented as a completed forensic finding at that point.

Later clarification

On August 8, 2022, the Solana Foundation reported that the draining activity began at 22:37 UTC on August 2 and continued for approximately four hours. Its later review counted 9,231 wallets and approximately $4.1 million in assets, said private-key material had been inadvertently transmitted by Slope to an application-monitoring service, and reaffirmed that Solana’s core protocol was not involved. It still did not establish exactly how the attacker obtained or intercepted that material. The later figures use a different investigation window and valuation basis from Elliptic’s August 3 estimate, so the apparent difference should not be interpreted as a calculated recovery or price movement.

Primary sourceSolana Status — initial drained-wallet investigation thread, August 3, 2022

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.