Solana hoses down ‘inaccurate’ CertiK report on Saga cellphone safety flaws

by Jeremy

A latest video from blockchain safety agency CertiK made a sequence of “inaccurate” claims a couple of potential safety vulnerability in Solana’s crypto-enabled Saga cellphone, Solana Labs has mentioned. 

In a Nov. 15 put up on X (previously Twitter), CertiK claimed the Saga cellphone contained a “essential vulnerability” generally known as a “bootloader unlock” assault which might supposedly permit a malicious actor to put in a hidden backdoor within the cellphone.

In a report despatched to Cointelegraph, CertiK claimed the bootloader unlock would “permit an attacker with bodily entry to a cellphone to load customized firmware containing a root backdoor.”

“We exhibit that this may compromise probably the most delicate information saved on the cellphone, together with cryptocurrency non-public keys,” CertiK’s report mentioned.

Nonetheless, a Solana Labs spokesperson advised Cointelegraph that CertiK’s claims are inaccurate, and its video didn’t reveal any reliable risk to the Saga gadget.

“The CertiK video doesn’t reveal any identified vulnerability or safety risk to Saga holders.”

Android’s inner Open Supply Venture documentation exhibits unlocking a bootloader may be carried out throughout a variety of Android gadgets.

Solana Labs mentioned to unlock the bootloader and set up customized firmware, an attacker must undergo a number of steps, which might solely be carried out after unlocking the gadget with the consumer’s passcode or fingerprint.

“Unlocking the bootloader wipes the gadget, which customers are alerted about a number of occasions when unlocking the bootloader, so it’s not a course of that may happen with out customers’ energetic participation or consciousness,” Solana Labs mentioned.

Associated: Making real-world blockchain options doable — Solana co-founder Raj Gokal

Moreover, if anybody proceeds to unlock the bootloader on an Android gadget, they’re subjected to a sequence of warnings in regards to the implications of the method.

In the event that they ignore these warnings, the gadget shall be wiped together with their non-public keys.

The Solana Saga cellphone was launched in April 2022 for a $1,099 price ticket. The cellphone presents a Web3-native DApp retailer in a bid to combine crypto apps into tech {hardware}.

4 months after launch, nonetheless, Solana slashed its worth to $599 — following a steep decline in gross sales.

CertiK didn’t instantly reply to a request for touch upon Solana Labs’ rebuttal.

Journal: I spent every week working in VR. It was principally horrible, nonetheless…