Summary
Slope Wallet (Slope Finance) was a Solana-based mobile cryptocurrency wallet that suffered a catastrophic security breach on August 2, 2022, in which over 9,200 wallets were drained of approximately $4–8 million in assets due to the app transmitting users' unencrypted seed phrases to a third-party telemetry service (Sentry). The root cause was a severe security misconfiguration by Slope Finance, in which the mobile application logged plaintext private key material without proper scrubbing. No formal victim compensation was established, the team declined to publicly accept responsibility, and founder Leal Cheung subsequently launched a new project (zkME) without resolution for affected users.
Connected Entities
1 entitiesTimeline(12 events)
2021-09
Slope Finance launches Slope Wallet mobile application on Solana.
2022-02-24
Slope Finance closes $8 million Series A funding round co-led by Solana Ventures and Jump Capital.
2022-08-02
Attack begins at 22:37 UTC. Attacker drains 9,229 wallets over approximately 7 hours, stealing an estimated $4.1–8 million in assets.
2022-08-03
Solana developers and security researchers publicly attribute the exploit to Slope Wallet's Sentry misconfiguration. Solana Foundation confirms no protocol-level vulnerability.
2022-08-03
Slope Finance offers a 10% bounty to the attacker for return of 90% of stolen funds within 48 hours. No response from attacker.
2022-08-04
Security firm OtterSec and others confirm that Slope's app transmitted seed phrases in plaintext to centralized Sentry servers. The Block publishes findings.
2022-08-10
Sentry publishes its own post-mortem, clarifying that Slope Finance failed to configure available data-scrubbing settings.
2022-08
Slope Finance publishes its Digital Forensics and Incident Response (DFIR) report acknowledging the Sentry vulnerability but concluding it cannot 'conclusively explain' the full hack.
2022-08
Victims organize under slopeaction.org seeking reimbursement and a formal acknowledgment of culpability.
2023-03
ZachXBT observes hacker addresses becoming active again, laundering funds from original theft addresses on Solana.
2023-10
ZachXBT publishes on-chain analysis tracing stolen funds from Solana through Binance nested exchanges, Tornado Cash (322 ETH), SWFT bridge to TRON, and into OTC cash-out addresses.
2023-10
ZachXBT warns the public to avoid zkME, a new project allegedly founded by Slope Wallet's Leal Cheung following abandonment of Slope Finance.
Decision Log
- hash: 5dnTj3pibUQ3xdsMetpt1PwTcCrz5JrP2XMP6rKuhyUq
- hash: 3Av3HjSTK1mTRFtJh32WswtEVW74PbrZbr9vFqUyie6x
- hash: 4HQUL4X2pT3GuRLXoUxDxNga1uJncTaKkNHxrXsVU9v4
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:48 AM
last updated: 6/15/2026, 7:30:07 PM
avoid.net — verified advice for a post-truth world