Squads detected an active address poisoning campaign where attackers create fake multisig accounts using vanity addresses designed to closely mimic legitimate ones, aiming to trick users into sending funds to attacker-controlled wallets. No users have been impacted so far. The protocol urges users to ignore any multisig they didn't create or weren't explicitly added to by their team — a social engineering play exploiting address similarity rather than any protocol-level vulnerability.

TLDR by @Benthic

More coverage

Explore the topic

More on Solana

Comments