Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Solana Labs

Solana Labs Vendor Cyber Rating & Cyber Score

solanalabs.com

Solana Labs builds products, tools and reference implementations that can be used on the Solana blockchain. This is the official account of Solana Labs, Inc


Solana Labs A.I CyberSecurity Scoring

Solana Labs
Company Information
Website:https://solanalabs.com/
Employees number:261
Number of followers:100,100
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:solanalabs.com
Solana Labs Risk Score (AI oriented)
Between 650 and 699
logo
Solana LabsTechnology, Information and Internet
Updated:
03/04/2026
672/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Solana Labs Global Score (TPRM)
xxxx
logo
Solana LabsTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Solana Labs
Solana LabsWeak
Current Score
672B (WEAK)
01000
3 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
677Before Incident
MAY 2026
675Before Incident
APRIL 2026
674Before Incident
MARCH 2026
691Before Incident
Cyber Attack
23 Mar 2026Solana Labs
npm, Solana and Ethereum: Five Malicious npm Packages Target Crypto Developers, Steal Wallet Keys via Telegram

Malicious npm Packages Target Solana and Ethereum Developers in Supply Chain Attack

672After Incident
CRITICAL-19
NPMSOLETH1774427254
Malicious npm Packages Target Solana and Ethereum Developers in Supply Chain Attack A recent supply chain attack has compromised cryptocurrency developers by distributing five malicious npm packages that steal wallet private keys and exfiltrate them to a Telegram-based command-and-control (C2) server. The packages, published under the npm account galedonovan, impersonate legitimate crypto libraries to target both Solana and Ethereum ecosystems. The identified packages raydium-bs58, base-x-64, bs58-basic, ethersproject-wallet, and the briefly published base_xd were designed to intercept private key operations. For Solana developers, the packages hijack Base58 decode() calls, while the Ethereum-focused ethersproject-wallet triggers malicious code within the Wallet constructor. In all cases, stolen keys are sent to a hardcoded Telegram bot (@Test20131_Bot) before legitimate operations complete, allowing attackers to drain compromised wallets. The attack leverages typosquatting and dependency confusion, with some packages (bs58-basic) containing no malicious code themselves but relying on base-x-64 to execute the theft. Obfuscation techniques, including array-rotation ciphers, were used to conceal the Telegram C2 endpoint, though one package (raydium-bs58) accidentally exposed the bot token and group invite URL in a comment. The campaign, active as of March 23, 2026, was discovered by Socket, which submitted takedown requests for the packages and the associated npm account. However, four of the five packages remained available in the registry at the time of analysis. The attack infrastructure relies solely on the Telegram bot, meaning exfiltration remains operational as long as the bot is active. Attribution artifacts such as shared typos in package.json, identical compiled binaries, and uniform file timestamps strongly suggest a single developer behind the campaign. The operator’s Telegram handle (@crypto_sol3) was linked to the bot’s administration group. The malicious packages exploit Node.js 18+ environments, failing silently on older versions due to a missing fetch() API dependency. Developers are advised to remove the affected packages and treat any exposed keys as compromised, though the summary strictly focuses on the incident’s details.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Financial gain through cryptocurrency theft
IMPACT
Data Compromised: Wallet private keysSystems Affected: Node.js 18+ environmentsOperational Impact: Compromised cryptocurrency walletsIdentity Theft Risk: High (private keys stolen)Payment Information Risk: High (cryptocurrency wallets drained)
DATA BREACH
Type Of Data Compromised: Wallet private keysSensitivity Of Data: High (cryptocurrency wallet access)Data Exfiltration: Yes (to Telegram C2 server)Personally Identifiable Information: Private keys (indirectly linked to identities)
FEBRUARY 2026
690Before Incident
JANUARY 2026
688Before Incident
DECEMBER 2025
686Before Incident
NOVEMBER 2025
686Before Incident
OCTOBER 2025
684Before Incident
SEPTEMBER 2025
683Before Incident
AUGUST 2025
681Before Incident
JULY 2025
680Before Incident
JANUARY 2025
726Before Incident
Breach
01 Jan 2025Solana Labs
Solana

Malicious npm and PyPI Packages Targeting Solana's Ecosystem

669After Incident
CRITICAL-57
SOL000012425
Malicious npm and PyPI packages were crafted to target Solana's ecosystem, with the intent to steal private keys and drain funds from victims' wallets. The operation involved typosquatting and names mimicking popular libraries, with the theft executed via Gmail SMTP servers to evade detection. Despite discovery and reporting, the malicious packages remained live at that time. Attackers rigged the packages to programmatically transfer the majority of wallet contents to their address, carefully leaving a small fraction to avoid raising immediate suspicion. Over 130 downloads were recorded for these packages, showcasing a targeted approach to siphon off Solana's assets via automated exfiltration.
INCIDENT DETAILS -
TYPE
Cyber Theft
MOTIVATION
Financial Gain
IMPACT
Private KeysWallet Funds
DATA BREACH
Private KeysWallet FundsSensitivity Of Data: HighData Exfiltration: Yes
AUGUST 2022
770Before Incident
Breach
01 Aug 2022Solana Labs
Solana Labs

Solana and Slope Wallet Data Breach

701After Incident
CRITICAL-69
SOL1127151122
Solana and Slope suffered from a data breach incident that affected Slope, a third-party wallet for Solana. The hardware wallets offered by Slope are still safe; the attack only affected the downloadable wallet program. The Solana Foundation noted that the Solana protocol itself is still secure despite the fact that thousands of wallets were drained. Customers should take action to protect their funds, the business further advised. It suggested that customers transfer their funds to a new wallet after creating a new seed phrase.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Wallet InformationSlope Wallet Program
DATA BREACH
Wallet Information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Solana Labs ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Solana Labs's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Solana Labs's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Solana Labs ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Solana Labs's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Solana Labs Cyber Scoring History | Rankiteo