Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Solana Dismisses CertiK Report On Saga Phone Vulnerability

Solana Dismisses CertiK Report On Saga Phone Vulnerability

Cryptodaily2023/11/16 10:48
By: Amara Khatri
BTC+1.14%SOL+1.59%XOLDTOKEN0.00%

Table of Contents

  • The CertiK Video
  • Solana Calls CertiK Claims Inaccurate
  • The Saga Phone

Solana Labs has dismissed a recent video by CertiK, stating that the blockchain security firm made several inaccurate claims about a potential security vulnerability in Solana’s Saga phone. 

Saga is Solana’s crypto-enabled Android phone and was released in April. The phone is designed to pair Web3 with smartphones. 

The CertiK Video 

CertiK, in a post on X (formerly Twitter) on the 15th of November, claimed that the Saga phone contained a critical vulnerability known as a “bootloader unlock” vulnerability. The vulnerability could give malicious actors a backdoor entry into the phone and compromise the initial software responsible for the starting of the device to be compromised. CertiK also claimed the bootloader vulnerability would allow any attacker with physical access to a phone to load custom firmware that contains a root backdoor. CertiK stated, 

“We demonstrate that this can compromise the most sensitive data stored on the phone, including cryptocurrency private keys. The boot loader is unlocked, and software integrity cannot be guaranteed. Any data stored on the device may be available to attackers. Do not store any sensitive data on the device.”

The message from CertiK indicates that the phone could be hacked. However, it isn’t yet clear if the vulnerability is unique to the Saga phone or if it could impact other Android devices. 

Solana Calls CertiK Claims Inaccurate 

However, Solana has dismissed CertiK’s concerns about any potential vulnerability in the Saga phone. Lead software engineer of mobile at Solana Labs, Steven Laver, stated that the CertiK video did not reveal any known vulnerability or security threat to Saga users. Instead, the video only demonstrates the user unlocking the bootloader, which Laver stated could be done on any Android device. 

“The CertiK video does not reveal any known vulnerability or security threat to Saga holders. The video shows the user unlocking the bootloader, which is something that can be done on many Android devices.”

Android’s internal Open Source Project documentation also shows that unlocking a bootloader is an action that can be performed across several Android devices. Laver further added, 

“Unlocking the bootloader is an advanced feature of Saga and is disabled by default. We believe in allowing users the choice of how they use their phone. However, unlocking the bootloader is not a security vulnerability – a user must explicitly allow such changes to be made to their device, and those changes can only be made by an authorized user of the phone.”

However, if the user or attacker proceeds to unlock the bootloader, they not only go through multiple warnings but their device is wiped, along with their private keys. Laver added that this process could not be done without the user’s awareness or active participation. The video then showed how the attacker could drain BTC from the wallet attached to the phone. However, it did not show Seed Vault in the video. Seed Vault protects supported digital assets and seeds. 

Seed Vault was announced in 2022 and can access the highest privileged security environment available on a device. This includes secure operating modes of the processor to dedicated Secure Elements, which ensure a secure transaction signing experience through UI components built into Android. 

The Saga Phone 

Saga was launched in April and was designed to pair the Web3 ecosystem with smartphones. Apart from traditional app stores, Solana also offers a separate app store. The phone allows users to have self-custody of their assets and keep them with them on the go. A few months after its launch, Solana slashed the price of Saga by 40%, from $1000 to $599.

At the time, the head of business operations for Solana Mobile, Emmett Hollyer, stated that price reduction was a common strategy employed in the consumer electronics business, particularly when it came to smartphones. 

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — HOLO/USDT!
Bitget Announcement2025/09/12 07:46
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

- FUN plunged 32.34% in 24 hours to $0.008938, marking a 541.8% monthly loss amid prolonged bearish trends. - Technical breakdowns, elevated selling pressure, and forced liquidations highlight deteriorating market sentiment and risk-off behavior. - Analysts identify key support below $0.0080 as critical, with bearish momentum confirmed by RSI (<30) and MACD indicators. - A trend-following backtest strategy proposes short positions based on technical signals to capitalize on extended downward trajectories.

Bitget-RWA2025/09/12 06:14
OPEN has dropped by 189.51% within 24 hours during a significant market pullback

- OPEN's price plummeted 189.51% in 24 hours to $0.8907, marking its largest intraday decline in history. - The token fell 3793.63% over 7 days, matching identical monthly and yearly declines, signaling severe bearish momentum. - Technical analysts cite broken support levels and lack of bullish catalysts as key drivers of the sustained sell-off. - Absence of stabilizing volume or reversal patterns leaves the market vulnerable to further downward pressure.

Bitget-RWA2025/09/12 06:14
New spot margin trading pair — LINEA/USDT!
Bitget Announcement2025/09/11 10:04

Trending news

More
1
New spot margin trading pair — HOLO/USDT!
2
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

Crypto prices

More
Bitcoin
Bitcoin
BTC
$116,616.85
+0.57%
Ethereum
Ethereum
ETH
$4,667.23
-0.21%
XRP
XRP
XRP
$3.06
-1.33%
Tether USDt
Tether USDt
USDT
$1
-0.03%
Solana
Solana
SOL
$243.89
-1.59%
BNB
BNB
BNB
$933.69
-0.94%
USDC
USDC
USDC
$0.9999
-0.00%
Dogecoin
Dogecoin
DOGE
$0.2806
-2.89%
TRON
TRON
TRX
$0.3514
-0.13%
Cardano
Cardano
ADA
$0.9006
-2.36%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter