Free editionEdition loading…Sourced reporting

PrivacyNews

The record of who got hit on Solana, how it happened, and which fake sites are circulating.
—
…Solana incidents on record
…Reported losses
…Incidents, past 12 months
…Listed Solana phishing domains
Top story

Compiling today's incident record

From the DefiLlama hacks catalogue

The front page is assembled from public records each time it is opened. Incidents appear below once the catalogue has been read.

The incident ledger

DefiLlama · Solana-tagged · newest first
Reading the catalogue…

Amounts are DefiLlama's estimates at the time of each incident. A dash means no figure was published.

The wire

Researcher feeds, merged
Collecting dispatches…

Drainer blotter

ScamSniffer open list

Loading roughly 350,000 listed domains…

Printed defanged, as text only. These are not links. Do not type them into a browser.

Letters to the editor

Reader questions

"Is every Solana incident here?"

No. The ledger holds what DefiLlama has catalogued under the Solana chain. Individual wallet drains, small rugs and most phishing losses never reach a public database.

"Why run stories about other chains?"

Attack techniques travel: approval abuse, leaked keys, hijacked front ends. Items that mention Solana or its apps carry a Solana slug so you can filter to them.

"Why is the blotter a week behind?"

ScamSniffer releases its open list with a seven-day delay and keeps the live feed for partners. An unlisted domain is not a safe one; open apps from your own bookmarks.

"I approved something bad. What now?"

Move whatever remains to a newly created wallet, revoke token delegates from a block explorer or your wallet's settings, and refuse anyone who asks for your recovery phrase to "fix" it. That request is the second half of the scam.