What went wrong, and where.
Solana hacks and exploits from DefiLlama, the latest write-ups from security researchers, and phishing domains that impersonate Solana apps. Every line links to its source.
Solana hacks and exploits.
Every entry DefiLlama tags with the Solana chain, newest first. Amounts are DefiLlama's estimates at the time; "—" means no amount was published.
Loading incidents…
How they happened
By DefiLlama classification, all Solana incidents.
From the researchers.
Latest posts from four public feeds, read server-side and merged. Posts that mention Solana or Solana apps are tagged; the rest are cross-chain context.
Reading feeds…
Fake Solana sites on the blocklist.
Domains from ScamSniffer's open phishing database whose names imitate Solana apps. Shown as text, never as links. Do not visit them.
Most recently listed
Loading the list (about 350,000 domains)…
Check a link before you click
Matches the domain and its parents against ScamSniffer and Phantom's open blocklist. Nothing is fetched from the site.
Which apps they copy
Count of listed domains by imitated brand.
How to read this.
Is this every Solana incident?
No. It is what DefiLlama has catalogued and tagged with the Solana chain. Wallet drains of individual users, small rugs and many phishing losses never make it into a public database.
Why are some write-ups not about Solana?
Most techniques (approval exploits, key compromises, front-end hijacks) repeat across chains. Posts that mention Solana or its apps get a SOLANA tag so you can filter to them.
Why is the drainer list a week old?
ScamSniffer publishes its open list with a 7-day delay and keeps the real-time feed for paying partners. A domain not being listed does not make it safe. Use bookmarks for the apps you use.
What should I do if I signed something bad?
Move remaining funds to a fresh wallet you control, revoke token delegates (see DelegateCheck), and never type your seed phrase into any site that asks for it to "fix" things. We never ask for your seed phrase.