Solana Fixes Confidential Token Vulnerability
By: bitcoin ethereum news|2025/05/05 16:45:01
0
Share
Solana Foundation fixes bug affecting Token-2022 and ZK ElGamal Proof that could have permitted unauthorized minting. Due to this bug, the attackers could have targeted the unhashed components by creating a fake identity that easily passes verification. The Solana Foundation has recently encountered a bug that allowed hackers to mint some tokens and even take those tokens from users’ accounts. However, the bug has been reportedly fixed now. The Foundation’s analysis reveals that the vulnerability was first found on April 16, and it could have permitted a hacker to proceed with an invalid proof affecting the privacy of the blockchain platform, permitting Token-22 confidential tokens. Also, it mentioned that no known exploit of the vulnerability has been reported, and since then, the validators of Solana have adopted the patched version. The bug primarily bothered two programs, Token-2022 and ZK ElGamal Proof. Token-2022 is responsible for managing the main app logic for token mints and accounts. On the other hand, ZK ElGamal Proof verified the accuracy of zero-knowledge proofs to show precise account balances. As per the foundation, some algebraic components were removed from the hash in the Fiat-Shamir Transformation’s transcript generation, which identifies the creation of public randomness using a cryptographic hash function. Due to this bug, the attackers could have targeted the unhashed components by creating a fake identity that easily passes verification to mint and steal Token-22 confidential tokens. To resolve this major issue, two patches were placed. The Centralization Scrutiny A lot of Solana validators, including Anza, Firedancer, and Jit,o adopted the patches after two days of encountering the issue. Other firms such as Asymmetric Research, Neodyme, and OtterSec also facilitated it. The Foundation also noted that no funds have been tampered with and it is safe till now. Regardless of this, the validators have raised centralization concerns within the crypto community. One of them was a Curve Finance contributor who was concerned about the close relationship of the Foundation with Solana validators. It mentioned that the main issue is that everything was done privately, and now the bad actors already know that these channels exist, and it is a centralized point of failure in a decentralized system. Highlighted Crypto News Today: Arizona Governor Blocks Bill to Hold Bitcoin in State Reserves Source: https://thenewscrypto.com/solana-fixes-confidential-token-vulnerability-sparks-centralization-debate/
You may also like

Interpreting the Anthropic vs. War Department Conflict: What Does Trump Intend to Do?
In the coming decades, our freedom may be more fragile than we think

Nasdaq Moves In, Predicts Market Has Reached Mainstream Inflection Point
Predictive trading is no longer just an experiment in the crypto space or a niche market but is starting to be integrated into the product suite of traditional trading platforms.

After a 48-hour ban, Claude reached the top of the App Store
Just the day before, ChatGPT was sitting right there

If this is the beginning of the triple halving, what are top investors saying about what to expect?
Hormuz Strait Blockade, Capital War, Oil and Bitcoin

After Iran's Political Risk Rises, Cryptocurrency Sees Massive Outflow
Following the airstrike, within minutes, Iran's largest cryptocurrency exchange, Nobitex, saw a 700% surge in cryptocurrency outflows.

Pantera Capital Partner: The Financial Trajectory of AI Agents
AI agents will move towards fully autonomous commerce, and blockchain is the only digital-native financial track that meets its needs for identity, micropayments, and trustless execution.

In the next 5 years, Vitalik will scale Ethereum like this
Short-Term vs Long-Term, Execution, Data vs State

Sam Altman and the End of the World Capitalism
The real danger is never AI itself, but those who believe they have the right to define the human destiny.

Wall Street Rings Inflation Alarm Bells Amid Iran Tensions, What Does It Mean for Cryptocurrency?
Interest rates have remained stubbornly high, posing a challenge to the cryptocurrency bull case.

Qwen Open Source Model Enters Mobile, Nasdaq Tests Water Prediction Market, What's the Overseas Crypto Community Talking About Today?
What Was the Hottest Topic Among Expats in the Last 24 Hours?

MegaETH Co-founder: 48 Hours After Escaping Dubai, I Reassess the Entire Crypto Scene
The global environment is not favorable to us, but in the long run, it may be favorable to us.

Morning Report | Strategy increased its holdings by 3,015 bitcoins last week; BitMine increased its holdings by 50,928 ETH last week; Vitalik elaborated on the Ethereum execution layer roadmap
March 2 Market Key Events Overview

Why is it said that there are structural opportunities in encrypted AI?
When centralized AI falls into the dilemma of regulation and trust, Crypto + AI will become a structural escape route for safeguarding data and sovereignty in a multipolar world.

Make Probability an Asset: A Forward-Looking Perspective on Predictive Market Agents
The predictive market agents are expected to present early prototypes in early 2026, likely becoming an emerging product form in the field of agents in the following year.

Consumer application issues
The truly outstanding applications will not ask people to "use cryptocurrency," but will provide practical and better solutions to the problems that people already face.

Arthur Hayes: The flames of war in the Middle East rise, Bitcoin is bullish
War is often accompanied by monetary easing, which may also become an important backdrop for driving up risk assets like Bitcoin.

Legendary investor Naval: In the AI era, traditional software engineers have no value?
You can always find a perfect niche that fits you and become a leader in that field.

More absurd than knowing about the war in advance is knowing in advance about the assassination of Soleimani
The temptation of a million dollars cannot be stopped by the calamity of prison.
Interpreting the Anthropic vs. War Department Conflict: What Does Trump Intend to Do?
In the coming decades, our freedom may be more fragile than we think
Nasdaq Moves In, Predicts Market Has Reached Mainstream Inflection Point
Predictive trading is no longer just an experiment in the crypto space or a niche market but is starting to be integrated into the product suite of traditional trading platforms.
After a 48-hour ban, Claude reached the top of the App Store
Just the day before, ChatGPT was sitting right there
If this is the beginning of the triple halving, what are top investors saying about what to expect?
Hormuz Strait Blockade, Capital War, Oil and Bitcoin
After Iran's Political Risk Rises, Cryptocurrency Sees Massive Outflow
Following the airstrike, within minutes, Iran's largest cryptocurrency exchange, Nobitex, saw a 700% surge in cryptocurrency outflows.
Pantera Capital Partner: The Financial Trajectory of AI Agents
AI agents will move towards fully autonomous commerce, and blockchain is the only digital-native financial track that meets its needs for identity, micropayments, and trustless execution.