CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Solana Patches Bug That Could Have Allowed Attackers to Mint and Swipe Tokens
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Solana Patches Bug That Could Have Allowed Attackers to Mint and Swipe Tokens
News

Solana Patches Bug That Could Have Allowed Attackers to Mint and Swipe Tokens

CoinRSS
Last updated: May 6, 2025 3:20 am
CoinRSS Published May 6, 2025
Share

Contents
In briefDaily Debrief Newsletter

In brief

  • Solana engineers patched a bug that affected Token-22 confidential tokens.
  • If exploited, an attacker could have minted unlimited quantities of tokens and withdrawn them from accounts.
  • The bug was patched quietly ahead of public disclosure, generating social media debate.

Solana network validators narrowly avoided catastrophe, rolling out a patch that killed a bug in a program that could have allowed exploiters to mint certain tokens in unlimited quantities—or withdraw them from any account. 

The vulnerability, which would have only affected Token-22 confidential tokens, was found in the ZK ElGamal Proof program, which certifies encrypted balances and verifies the accuracy of zero-knowledge proofs. 

“In the on-chain ZK ElGamal Proof program, some algebraic components were not included in a hash used to generate a transcript for the Fiat-Shamir Transformation,” a postmortem report from the Solana Foundation reads. “A sophisticated attacker could use these unhashed components to develop a forged proof of an unauthorized action that passes verification.”

In other words, an exploiter could have used the forged proof to mint unlimited quantities of Token-22 confidential tokens or withdraw them from accounts. 

The potential vulnerability was first reported to Anza Github Security Advisory on April 16 with a patch rolled out to validators directly the following day after evaluation and confirmation of the vulnerability from engineers at Anza, Firedancer, and Jito.

Anza is a Solana development shop comprised of former Solana Labs employees, while Jito is a noted infrastructure firm in the ecosystem. Firedancer is a Solana validator client in development from Jump Crypto.

Security firms Asymmetric Research, Neodyme, and OtterSec were also pulled in to provide support and review the patch. 

By the afternoon of April 18, a supermajority of validator operators adopted a fix, which included a second patch that was used to address a similar issue in another part of the codebase. With a patch now adopted, no funds are at risk and no known exploits of the vulnerability have been discovered.

Though the patch was quickly addressed and no funds are known to be exploited, the Solana Foundation faced some criticism across social media. Some users called out the behind-the-scenes upgrade, which took place two weeks before the Foundation addressed it publicly via the postmortem. 

“Am I hearing this right? There was a zero-day on Solana mainnet and >70% of the validators privately colluded to upgrade and patch the critical bug before it was even made public,” posted one pseudonymous Ethereum ecosystem developer on X (formerly Twitter).

The post drew pushback from notable Solana devs and Solana co-founder Anatoly Yakovenko in the process. Even longtime Ethereum developer Hudson Jameson weighed in, saying this approach was typical and necessary for fixing issues.

This is totally fine. Bitcoin, Zcash, and Ethereum have all had instances where the core devs needed to privately plan a secret bug fix. A good chain culture means having mature devs who can accomplish stealth fixes. pic.twitter.com/DA8pENn08D

— Hudson Jameson (@hudsonjameson) May 5, 2025

“This is totally fine,” said Jameson on X. “Bitcoin, Zcash, and Ethereum have all had instances where the core devs needed to privately plan a secret bug fix. A good chain culture means having mature devs who can accomplish stealth fixes.”

“I was involved in distributing this patch to validators before it was released publicly,” said Tim Garcia, validator relations lead at the Solana Foundation. “I’m happy to hear suggestions on a better process. Unfortunately, doing the distribution in public before sufficient adoption is a non-starter.”

This is hardly the first time that Solana has faced centralization critiques; notably, last October, famed whistleblower Edward Snowden called out the layer-1 blockchain over centralization. Solana ecosystem leaders pushed back, with Yakovenko saying, “As usual, Solana is decentralized only by objectively measurable metrics, and centralized across all the other ones.”

Solana currently boasts 1,279 validators, according to its website. 

Edited by Andrew Hayward

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

Bitcoin ETFs See Record-High Outflows of $672 Million

Crypto Bros Argue Trump Policy Shift Means $25M Fraud Case Should Be Tossed

Bitcoin Miner MARA Posts Record Quarterly Revenue, Beating Estimates

‘Santa Rally’ MIA as Bitcoin Falls to Lowest Price in a Month

Dogecoin Plummets to Lowest Price in a Month, Outpacing Bitcoin and XRP Losses

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article The BNB setup you can’t ignore! – DEX volume surge and a looming bear trap
Next Article Corporate Treasuries Will Add $330 Billion in Bitcoin by 2029: Bernstein
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Bitcoin, Dogecoin Targeted as Norway Eyes Ban on New Crypto Mining Operations
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?