[UPDATE from Solana]
This exploit was isolated to one wallet on Solana, and hardware wallets used by Slope remain secure.
While the details of exactly how this occurred are still under investigation, but private key information was inadvertently transmitted to an application monitoring service. 2/3
My god, so Slope was sending plain text private key and seed phrases to a server.
There is absolutely no acceptable design reason for that.
I expected a string appending somewhere incorrectly as a leak but this is labelled… what the hell?