This repository is a public safety notice for Solana builders, traders, and project owners.
This notice is not a call for harassment, threats, doxxing, retaliation, or mass reporting. Do not contact, threaten, harass, or target any individual mentioned here.
The purpose of this page is limited to documenting a security/payment incident and warning others to use strong precautions before sharing funds, private keys, API keys, server access, or production credentials with unknown third-party developers.
The following public identifiers were involved in the incident report:
- GitHub profile:
https://github.com/soldrift - GitHub username observed:
soldrift - Display name observed:
Soldrift - Telegram handle observed:
@devbeast5775
These identifiers are listed only to help other users recognize the same vendor/contact. No private personal information is published here.
A third-party Solana/web tooling developer relationship was initiated through Telegram.
The vendor presented themselves as a Solana tool developer and was given payment and server access for a Solana-related dashboard/bundler project.
After the incident, multiple security concerns were identified, including:
- wallet/private-key handling risk,
- server root-access risk,
- API-key/RPC-key exposure risk,
- unsafe operational setup risk,
- and payment-delivery concerns.
Because Solana tools may involve private keys, seed phrases, wallet funding, RPC keys, transaction signing, and server access, even a partially unsafe setup can create serious financial risk.
This notice is published to help other builders avoid sharing sensitive credentials or production access without independent code review, isolated testing, and strict wallet separation.
- A Solana/web tool development arrangement was discussed through Telegram.
- Payment was sent for development work.
- Server access was provided for setup/modification.
- A Solana-related tool/project was delivered or modified.
- After review, security and wallet-safety concerns were identified.
- Server access was removed and credentials were rotated.
- Wallets, API keys, and server configuration were reviewed.
- Evidence was preserved for platform reports, exchange reports, and potential legal follow-up.
This report does not publish the full private conversation because it may contain unrelated or sensitive private information.
Do not share the following with unknown or unverified third-party developers:
- private keys,
- seed phrases,
- wallet export files,
- API keys,
- RPC keys,
- dashboard passwords,
- server root access,
- production source-code access,
- funded wallets,
- or production credentials.
If you already shared any of the above, rotate them immediately and move funds to new wallets.
Recommended precautions:
- use disposable wallets only,
- test with very small amounts first,
- run tools only on isolated servers,
- remove developer access after setup,
- review
.envvalues manually, - verify safe-withdraw addresses,
- check for unexpected external URLs or webhooks,
- and confirm that API ports are not publicly exposed.
The following evidence has been preserved privately for reports and review:
- Telegram export,
- payment transaction records,
- wallet address records,
- TXID records,
- GitHub profile/repository screenshots,
- server logs,
- file snapshots,
- delivered project files,
- access timeline,
- payment timeline,
- and post-incident security review notes.
Only limited relevant screenshots or transaction identifiers may be shown publicly.
Add screenshots below.
Primary wallet observed:
E8RcJDs3SaBP2udWy6bD7576zJ3WitfbVh16vgeqoAgi
Related wallet observed:
5cZWa1KZQnMPeXTHPRF8JSEPMhzRaHPehAoG1rPtiHGc
Transaction reference:
33Jc35XrQwhFAZN93Gcsyi2a3Zb9ujgxNeSPcD2xUMzcQ3b18kqCUHHhUdzzAY5dNDgQHSfqFM7RshX7A4KvCnKW
Solscan reference:
https://solscan.io/tx/33Jc35XrQwhFAZN93Gcsyi2a3Zb9ujgxNeSPcD2xUMzcQ3b18kqCUHHhUdzzAY5dNDgQHSfqFM7RshX7A4KvCnKW
After the incident, the following actions were taken:
- developer access removed,
- server password rotated,
- SSH keys reviewed and removed,
- firewall rules reviewed,
- IPv6 SSH access restricted,
- API/RPC keys reviewed or rotated,
- exposed wallets abandoned or rotated,
.envand wallet data permissions restricted,- server ports reviewed,
- project files reviewed for unsafe behavior,
- and evidence archived.
This is a documented security and payment-risk notice.
It is not an instruction to harass, threaten, doxx, or retaliate against anyone.
Builders should independently verify developers, isolate test environments, avoid sharing private keys, and never fund third-party tools with production wallets until the code, server access, wallet flow, and withdrawal paths have been reviewed.