Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds
By: crypto news|2025/05/05 18:15:01
0
Share
The Solana Foundation has addressed a critical bug in its privacy-focused token system that, if exploited, could have allowed malicious actors to forge zero-knowledge proofs and perform unauthorized token minting or withdrawals.The flaw was disclosed on April 16 via a GitHub advisory posted by Anza, a Solana development team, along with a working proof-of-concept.Engineers from Anza, Firedancer, and Jito promptly confirmed the issue and began remediation efforts, according to a post-mortem published Saturday.Solana Bug Traced to ZK ElGamal Proof SystemAt the core of the vulnerability was the ZK ElGamal Proof program, which validates zero-knowledge proofs (ZKPs) used in Solana’s Token-22 confidential transfers.These token extensions are designed to enable privacy-preserving transactions by encrypting token balances and using cryptographic proofs to validate transfers.Zero-knowledge proofs allow users to prove the validity of a transaction without revealing sensitive information, such as the amount or recipient address.However, in this instance, a key algebraic component was missing from the hashing process used in the Fiat-Shamir transformation—a common technique that converts interactive proofs into non-interactive ones suitable for blockchain verification.The oversight created a potential backdoor where sophisticated attackers could craft fake proofs that would be mistakenly accepted by the on-chain verifier.Such an exploit could have enabled unauthorized minting of tokens or withdrawals from wallets without permission.Fortunately, the vulnerability did not affect standard SPL tokens or the main Token-2022 logic.Where is the line between esoteric threat to the network of infinite mint risk and roughly 0 risk of application layer bug on contract with roughly 0 usage?Also they didn't secretly upgrade anything they published an update without mentioning the bug and publicly engaged— Block Enthusiast (@BlockEnthusiast) May 5, 2025Private patches were quickly distributed to validator operators on April 17, with a second patch released later that day to address a related issue.External security firms Asymmetric Research, Neodyme, and OtterSec reviewed the fixes.By April 18, the majority of validators had implemented the patch.According to Solana’s post-mortem, there is no evidence the flaw was ever exploited, and all user funds remain safe.Solana Leads Blockchain Revenue Race in Q1 2025Solana has taken the lead among blockchain networks in Q1 2025, outpacing competitors like Ethereum and BNB Chain in total revenue.This marks a major milestone for the high-speed blockchain, driven by a surge in user engagement and an expanding ecosystem.The network’s revenue boost was powered by increased decentralized app (dApp) usage, NFT transactions, and overall on-chain activity.Solana’s scalable architecture and low fees continue to attract developers and users alike, making it a preferred platform for high-volume applications.Its growth was further supported by upgrades, strategic partnerships, and momentum in sectors like DeFi, gaming, and mobile crypto apps.These developments have solidified Solana’s reputation as a user-friendly, high-performance blockchain with a strong outlook for the rest of 2025.The post Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds appeared first on Cryptonews.
You may also like

China's AI Compute Power Counterstrike
The cost itself is the progress.

Global Assets Plunge: Hormuz, Chips, and a South Korean Holiday
The Dollar Wins, Everyone Else Loses

Bloomberg has reported twice, Hyperliquid once again in Wall Street's radar
Weekend Front-Running

Trump Backs Crypto Bill, SEC Halts Leveraged ETF, What Is the English-Speaking Crypto Community Talking About?
What Was Hot in the Last 24 Hours Among Expats?

OpenClaw Floods Into Polymarket, Some Making Tens of Thousands Per Month
Are you ready to venture into Polymarket and dive into the shrimp farming craze?

Understanding Trump's "Warfare Playbook": Ten Signals Investors Must Know
Debriefing Trump's series of conflicts over the past year, this article outlines ten stages of Trump's conflict strategy, revealing the underlying logic between war, market fluctuations, and eventual negotiation.

Iranian Missile Heading Toward UAE, Claude Also Within Range
On March 1st, an Iranian missile struck an Amazon data center in the UAE. On the same day, Claude experienced a worldwide outage.

Successive Core Team "Heroes" Depart, Has Aave's DAO Dream Crumbled?
「This is not a matter of right or wrong, but rather a situation where existing governance mechanisms have not provided an effective resolution when interests and positions are misaligned.」

Is This the Year of the Robot? A Deep Dive into Robotics Projects
What are some noteworthy projects in the Robotic Race track?

When AI Takes Over Money: Bitcoin Becomes the "First Choice," Fiat Is Left Out
AI's view on "what makes a good currency" is already quite consistent.
AI Trading in Live Markets: 4 Lessons From a WEEX Hackathon Top 10 Finalist
AI trading meets real markets. Explore 4 lessons from a WEEX Hackathon Top 10 finalist on surviving volatility, trusting AI models, and building smarter crypto trading systems.

MegaETH Co-founder: 48 Hours After Leaving Dubai, I Reassessed the Entire Crypto Space
In an era of technological upheaval, rather than pursuing the "legitimacy" co-opted by power, it is better to sharpen the blade and build parallel systems that truly expand individual sovereignty.

Web3 Winter Mass Exodus: Resignations, Closures, Transformations, and Acquisitions
The intense collision between technology and capital, products and markets, vision and reality, each story reflects the confusion and unwillingness of the market participants.

Key Market Information Discrepancy on March 4th — A Must-Read! | Alpha Morning Report
1. Top News: Strait of Hormuz Emerges as Flashpoint in US-Iran Standoff, US Stocks Trim Losses, Asia-Pacific Markets Open Sharply Lower, Cryptocurrencies See Slight Recovery
2. Token Unlock: None

During the weekend market closure, Hyperliquid more accurately predicted the Gold reopening price than Binance
When markets are closed and real-time pricing is needed due to geopolitical risks, Hyperliquid takes the lead and is closer to the eventual futures reopening price.

OpenClaw thrusts crypto project Venice.ai into the spotlight as its token VVV surges over 500% in a single month
Openclaw Founder Advises Young People "Not to Waste Time on Cryptocurrency," Yet in its official documentation, it lists the cryptocurrency project Venice.ai as a recommended model provider.

Different Rulings in Similar Cases: Why can Uniswap go free while Tornado Cash cannot?
Time and tide wait for no man.

In the next 5 years, Vitalik will expand Ethereum in this way
Short-term and long-term, execution, data and status
China's AI Compute Power Counterstrike
The cost itself is the progress.
Global Assets Plunge: Hormuz, Chips, and a South Korean Holiday
The Dollar Wins, Everyone Else Loses
Bloomberg has reported twice, Hyperliquid once again in Wall Street's radar
Weekend Front-Running
Trump Backs Crypto Bill, SEC Halts Leveraged ETF, What Is the English-Speaking Crypto Community Talking About?
What Was Hot in the Last 24 Hours Among Expats?
OpenClaw Floods Into Polymarket, Some Making Tens of Thousands Per Month
Are you ready to venture into Polymarket and dive into the shrimp farming craze?
Understanding Trump's "Warfare Playbook": Ten Signals Investors Must Know
Debriefing Trump's series of conflicts over the past year, this article outlines ten stages of Trump's conflict strategy, revealing the underlying logic between war, market fluctuations, and eventual negotiation.