Guide · x402

An incident-response procedure for a suspected Solana wallet compromise: stopping inter…

An incident-response procedure for a suspected Solana wallet compromise: stopping interaction and preserving evidence before it's lost, distinguishing key/seed compromise from a single malicious approval, creating a verifiably clean new wallet on a clean devi…

by Saylor Innovations Knowledge Base · verified provider · updated 2026-09-22

What it does

An incident-response procedure for a suspected Solana wallet compromise: stopping interaction and preserving evidence before it's lost, distinguishing key/seed compromise from a single malicious approval, creating a verifiably clean new wallet on a clean device, inventorying and safely moving remaining assets with minimum signing, rotating related accounts, and permanently retiring the compromised address rather than reusing it once "quiet."

Capabilities

  • Drained-Wallet Incident Guide — a 7-minute technical guide

Tags: security & opsec · intermediate · wallet-compromise · incident-response · seed-phrase · phishing · solana

Use with an agent

  1. Discover. Agents find this listing with GET https://bazaar.saylorinnovations.com/discovery/search?query=…, the MCP tool search_resources, or /discovery/resources.
  2. Inspect. Fetch /resources/drained-wallet-incident.json for the price and payment options.
  3. Pay. Call GET https://saylorinnovations.com/api/kb?id=drained-wallet-incident. The provider answers 402 with its payment requirements. An x402 client signs one of the options below and retries with PAYMENT-SIGNATURE.
  4. Execute. The provider returns 200 with the data. Agent Bazaar is not in the request path and never sees your payment.

For humans

You don't need an account or an API key; you need a wallet holding a small amount of USDC or USDT on Solana, Base, Polygon, Arbitrum One, and an x402-capable client (see the examples below). Call the endpoint unpaid first to see exactly what it asks for.

Pricing & payment

Price
$0.02 / request
Protocol
x402 v2
Auth
No account or API key. Pay per request.
Networks
Solana, Base, Polygon, Arbitrum One

x402 payment requirements

SchemeNetworkAssetAmountPay toTimeout
exactSolana
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
USDC$0.027LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7120s
exactSolana
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
USDT$0.027LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7120s
exactBase
eip155:8453
USDC$0.020xf8A376eBF123D7252cd7b66bcD77A727a4def22f120s
exactPolygon
eip155:137
USDC$0.020xf8A376eBF123D7252cd7b66bcD77A727a4def22f120s
exactArbitrum One
eip155:42161
USDC$0.020xf8A376eBF123D7252cd7b66bcD77A727a4def22f120s
accepts[] (raw JSON)
[
  {
    "scheme": "exact",
    "network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
    "payTo": "7LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7",
    "asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
    "amount": "20000",
    "amountUsd": 0.02,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
    "payTo": "7LSjfrJf8fNsB8VA9u7N3WEn25smQLpob3SvyUvXacy7",
    "asset": "Es9vMFrzaCERmJfrF4H2FYD4KCoNkY11McCe8BenwNYB",
    "amount": "20000",
    "amountUsd": 0.02,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "eip155:8453",
    "payTo": "0xf8A376eBF123D7252cd7b66bcD77A727a4def22f",
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "amount": "20000",
    "amountUsd": 0.02,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "eip155:137",
    "payTo": "0xf8A376eBF123D7252cd7b66bcD77A727a4def22f",
    "asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
    "amount": "20000",
    "amountUsd": 0.02,
    "maxTimeoutSeconds": 120
  },
  {
    "scheme": "exact",
    "network": "eip155:42161",
    "payTo": "0xf8A376eBF123D7252cd7b66bcD77A727a4def22f",
    "asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
    "amount": "20000",
    "amountUsd": 0.02,
    "maxTimeoutSeconds": 120
  }
]

Examples

curl
curl "https://saylorinnovations.com/api/kb?id=drained-wallet-incident"
# -> 402 Payment Required, accepts[] lists how to pay
# retry with a PAYMENT-SIGNATURE (or PAYMENT header) once paid
JavaScript
const res = await fetch("https://saylorinnovations.com/api/kb?id=drained-wallet-incident");
if (res.status === 402) {
  const { accepts } = await res.json();
  // pay one of accepts[] via an x402 client, then retry with the payment header
}
Python
import httpx
res = httpx.get("https://saylorinnovations.com/api/kb?id=drained-wallet-incident")
if res.status_code == 402:
    accepts = res.json()["accepts"]
    # pay one of accepts[] via an x402 client, then retry with the payment header

Details

Provider
Saylor Innovations Knowledge Base
Endpoint
https://saylorinnovations.com/api/kb?id=drained-wallet-incident
License
LicenseRef-Saylor-Agent-Use-1.0
Machine-readable
/resources/drained-wallet-incident.json