• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Analysis

Solana Patches Bug That Could Have Allowed Attackers to Mint and Swipe Tokens

admin by admin
May 5, 2025
in Analysis
0
Solana Patches Bug That Could Have Allowed Attackers to Mint and Swipe Tokens
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

In brief

  • Solana engineers patched a bug that affected Token-22 confidential tokens.
  • If exploited, an attacker could have minted unlimited quantities of tokens and withdrawn them from accounts.
  • The bug was patched quietly ahead of public disclosure, generating social media debate.

Solana network validators narrowly avoided catastrophe, rolling out a patch that killed a bug in a program that could have allowed exploiters to mint certain tokens in unlimited quantities—or withdraw them from any account. 

The vulnerability, which would have only affected Token-22 confidential tokens, was found in the ZK ElGamal Proof program, which certifies encrypted balances and verifies the accuracy of zero-knowledge proofs. 

Related articles

Melania Trump Uses AI to Narrate Her New Memoir

Melania Trump Uses AI to Narrate Her New Memoir

May 23, 2025
Global Darknet Bust Leads to 0M in Digital Asset and Cash Seizures

Global Darknet Bust Leads to $200M in Digital Asset and Cash Seizures

May 23, 2025

“In the on-chain ZK ElGamal Proof program, some algebraic components were not included in a hash used to generate a transcript for the Fiat-Shamir Transformation,” a postmortem report from the Solana Foundation reads. “A sophisticated attacker could use these unhashed components to develop a forged proof of an unauthorized action that passes verification.”

In other words, an exploiter could have used the forged proof to mint unlimited quantities of Token-22 confidential tokens or withdraw them from accounts. 

The potential vulnerability was first reported to Anza Github Security Advisory on April 16 with a patch rolled out to validators directly the following day after evaluation and confirmation of the vulnerability from engineers at Anza, Firedancer, and Jito.

Anza is a Solana development shop comprised of former Solana Labs employees, while Jito is a noted infrastructure firm in the ecosystem. Firedancer is a Solana validator client in development from Jump Crypto.

Security firms Asymmetric Research, Neodyme, and OtterSec were also pulled in to provide support and review the patch. 

By the afternoon of April 18, a supermajority of validator operators adopted a fix, which included a second patch that was used to address a similar issue in another part of the codebase. With a patch now adopted, no funds are at risk and no known exploits of the vulnerability have been discovered.

Though the patch was quickly addressed and no funds are known to be exploited, the Solana Foundation faced some criticism across social media. Some users called out the behind-the-scenes upgrade, which took place two weeks before the Foundation addressed it publicly via the postmortem. 

“Am I hearing this right? There was a zero-day on Solana mainnet and >70% of the validators privately colluded to upgrade and patch the critical bug before it was even made public,” posted one pseudonymous Ethereum ecosystem developer on X (formerly Twitter).

The post drew pushback from notable Solana devs and Solana co-founder Anatoly Yakovenko in the process. Even longtime Ethereum developer Hudson Jameson weighed in, saying this approach was typical and necessary for fixing issues.

This is totally fine. Bitcoin, Zcash, and Ethereum have all had instances where the core devs needed to privately plan a secret bug fix. A good chain culture means having mature devs who can accomplish stealth fixes. https://t.co/ffKDqshki6 pic.twitter.com/DA8pENn08D

— Hudson Jameson (@hudsonjameson) May 5, 2025

“This is totally fine,” said Jameson on X. “Bitcoin, Zcash, and Ethereum have all had instances where the core devs needed to privately plan a secret bug fix. A good chain culture means having mature devs who can accomplish stealth fixes.”

“I was involved in distributing this patch to validators before it was released publicly,” said Tim Garcia, validator relations lead at the Solana Foundation. “I’m happy to hear suggestions on a better process. Unfortunately, doing the distribution in public before sufficient adoption is a non-starter.”

This is hardly the first time that Solana has faced centralization critiques; notably, last October, famed whistleblower Edward Snowden called out the layer-1 blockchain over centralization. Solana ecosystem leaders pushed back, with Yakovenko saying, “As usual, Solana is decentralized only by objectively measurable metrics, and centralized across all the other ones.”

Solana currently boasts 1,279 validators, according to its website. 

Edited by Andrew Hayward

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





#Solana #Patches #Bug #Allowed #Attackers #Mint #Swipe #Tokens

Tags: allowedAttackersBugmintPatchesSolanaSwipeTokens
Share76Tweet47

Related Posts

Melania Trump Uses AI to Narrate Her New Memoir

Melania Trump Uses AI to Narrate Her New Memoir

by admin
May 23, 2025
0

In brief U.S. First Lady Melania Trump has released an AI-narrated audiobook of her memoir, available exclusively via the ElevenReader...

Global Darknet Bust Leads to 0M in Digital Asset and Cash Seizures

Global Darknet Bust Leads to $200M in Digital Asset and Cash Seizures

by admin
May 23, 2025
0

In brief Operation RapTor resulted in 270 arrests across 10 countries and the seizure of $200 million in cash and...

Trump’s Meme Coin Dinner Draws Protests Calling For End to ‘Crypto Corruption’

Trump’s Meme Coin Dinner Draws Protests Calling For End to ‘Crypto Corruption’

by admin
May 23, 2025
0

In brief Protesters carried signs like "Grift Gala" and "America is not for sale" as Trump dined with $TRUMP token...

America’s Biggest Banks Consider Teaming Up to Challenge 5B Stablecoin Market: WSJ

America’s Biggest Banks Consider Teaming Up to Challenge $245B Stablecoin Market: WSJ

by admin
May 23, 2025
0

In brief Major U.S. banks, including JPMorgan and Bank of America, are reportedly exploring a shared stablecoin project. The move...

Anthropic’s Claude 4 Arrives, Obliterating AI Rivals—And Budgets Too

Anthropic’s Claude 4 Arrives, Obliterating AI Rivals—And Budgets Too

by admin
May 23, 2025
0

In brief Claude 4 finally launched after long delays, crushing GPT-4.1 and Gemini 2.5 Pro on SWE-bench coding benchmarks. The...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Melania Trump Uses AI to Narrate Her New Memoir

Melania Trump Uses AI to Narrate Her New Memoir

May 23, 2025
Hyperliquid backs 24/7 crypto trading in CFTC comments submission

Hyperliquid backs 24/7 crypto trading in CFTC comments submission

May 23, 2025
TRUMP gala dinner attendees dump tokens before event as price falls 8% amid protests

TRUMP gala dinner attendees dump tokens before event as price falls 8% amid protests

May 23, 2025
Cetus offers M bounty after 0M hack as Sui faces decentralization debate

Cetus offers $6M bounty after $220M hack as Sui faces decentralization debate

May 23, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com