Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds
By: crypto news|2025/05/05 18:15:01
0
Share
The Solana Foundation has addressed a critical bug in its privacy-focused token system that, if exploited, could have allowed malicious actors to forge zero-knowledge proofs and perform unauthorized token minting or withdrawals.The flaw was disclosed on April 16 via a GitHub advisory posted by Anza, a Solana development team, along with a working proof-of-concept.Engineers from Anza, Firedancer, and Jito promptly confirmed the issue and began remediation efforts, according to a post-mortem published Saturday.Solana Bug Traced to ZK ElGamal Proof SystemAt the core of the vulnerability was the ZK ElGamal Proof program, which validates zero-knowledge proofs (ZKPs) used in Solana’s Token-22 confidential transfers.These token extensions are designed to enable privacy-preserving transactions by encrypting token balances and using cryptographic proofs to validate transfers.Zero-knowledge proofs allow users to prove the validity of a transaction without revealing sensitive information, such as the amount or recipient address.However, in this instance, a key algebraic component was missing from the hashing process used in the Fiat-Shamir transformation—a common technique that converts interactive proofs into non-interactive ones suitable for blockchain verification.The oversight created a potential backdoor where sophisticated attackers could craft fake proofs that would be mistakenly accepted by the on-chain verifier.Such an exploit could have enabled unauthorized minting of tokens or withdrawals from wallets without permission.Fortunately, the vulnerability did not affect standard SPL tokens or the main Token-2022 logic.Where is the line between esoteric threat to the network of infinite mint risk and roughly 0 risk of application layer bug on contract with roughly 0 usage?Also they didn't secretly upgrade anything they published an update without mentioning the bug and publicly engaged— Block Enthusiast (@BlockEnthusiast) May 5, 2025Private patches were quickly distributed to validator operators on April 17, with a second patch released later that day to address a related issue.External security firms Asymmetric Research, Neodyme, and OtterSec reviewed the fixes.By April 18, the majority of validators had implemented the patch.According to Solana’s post-mortem, there is no evidence the flaw was ever exploited, and all user funds remain safe.Solana Leads Blockchain Revenue Race in Q1 2025Solana has taken the lead among blockchain networks in Q1 2025, outpacing competitors like Ethereum and BNB Chain in total revenue.This marks a major milestone for the high-speed blockchain, driven by a surge in user engagement and an expanding ecosystem.The network’s revenue boost was powered by increased decentralized app (dApp) usage, NFT transactions, and overall on-chain activity.Solana’s scalable architecture and low fees continue to attract developers and users alike, making it a preferred platform for high-volume applications.Its growth was further supported by upgrades, strategic partnerships, and momentum in sectors like DeFi, gaming, and mobile crypto apps.These developments have solidified Solana’s reputation as a user-friendly, high-performance blockchain with a strong outlook for the rest of 2025.The post Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds appeared first on Cryptonews.
You may also like

SBF's little brother turned 225 million into 5.5 billion in one year
Let’s meet the 24-year-old new "stock god" of AI.

In a World of Disruption, How Can Humanities Workers Better Use AI?
This AI in Practice experience is not about teaching you a few magical keywords to memorize; it's more like a methodology.

Anthropic Open Letter: The Hypocritical Sam Altman, PUA Master
OpenAI's extensive PR rhetoric with the Department of War on these issues is either lying or deliberately creating confusion. These facts reveal a pattern of behavior, a pattern I have seen many times in Sam Altman, and I hope everyone can recognize it

On the same day that Kraken's Fedmaster Account was approved, the banking lobbying group immediately launched a counterattack.
Banking Lobby Group Slams Kraken's Approval for "Limited Purpose" Fed Master Account.

Bitwise: This weekend's attack accelerated the on-chain migration of the financial world
The never-ending market has become a global obsession.

Market Downturn: Which Assets Are Worth Watching?
"Whether it can bring benefits to the holder" is one of the key reference indicators.

The real opportunity of stablecoins is not to kill Visa
In the new merchant ecosystem born in the AI era, stablecoins will become the first widely adopted payment infrastructure.

Trump's AI Farce: Insult if You Don't Pay
Dario's all-hands email is full of ad hominem attacks
US & Canada Crypto Tax Season 2026: Official Tax Reporting Support from WEEX × KoinX
Prepare for US & Canada crypto tax season 2026. Learn how to export your WEEX transaction history and access official reporting support through our partnership with KoinX.

Conversation between Tom Lee and "The Big Short" Author: AI has detected bubble signal, crypto correction due to gold liquidity being "siphoned off"
A real bubble occurs when everyone is absolutely certain that "this is definitely not a bubble."

The true reason for Claude's ban, Kraken accessing the Federal Reserve payment system, What is the English community paying attention to?
What Was Trending in the Last 24 Hours?

「Buying the Dip」 of 400,000 BTC: Is $74,000 a Rebound or a Reversal?
BTC price hits a new monthly high.

OpenClaw, Another Batch of Middle Class Jobless
Time will not wait for anyone.

Morning News | Backpack will launch on-chain IPO subscription service; Predict.fun strategically acquires on-chain prediction platform Probable; SoFi partners with Mastercard for strategic cooperation
March 4 Market Important Events Overview

Inventorying the Washington power in the crypto space, who is speaking out for U.S. crypto legislation?
From ideology to ecological initiatives, the lobbying power of American cryptocurrency is undergoing a comprehensive evolution, ushering in a new era of specialized and refined policy games.

650 million dollars, 1.5 billion dollars, 2 billion dollars, the crypto VC landscape has changed!
Homogenized industries are ultimately fragile; only when different species can emerge does the market truly come alive.

Why prediction markets are the largest untapped collateral pool in DeFi
From "gambling" to "financable assets": prediction markets are becoming the next hundred billion collateral pool in DeFi, opening new frontiers of capital efficiency.
500% XAUT Staking, Zero-Fee Gold Futures and $100K Rewards: Why Traders Are Turning to WEEX for Tokenized Gold
Explore WEEX's $100,000+ gold campaign featuring 500% XAUT staking, zero-fee gold contracts, and $30,000 PAXG rewards. Trade tokenized gold today.
SBF's little brother turned 225 million into 5.5 billion in one year
Let’s meet the 24-year-old new "stock god" of AI.
In a World of Disruption, How Can Humanities Workers Better Use AI?
This AI in Practice experience is not about teaching you a few magical keywords to memorize; it's more like a methodology.
Anthropic Open Letter: The Hypocritical Sam Altman, PUA Master
OpenAI's extensive PR rhetoric with the Department of War on these issues is either lying or deliberately creating confusion. These facts reveal a pattern of behavior, a pattern I have seen many times in Sam Altman, and I hope everyone can recognize it
On the same day that Kraken's Fedmaster Account was approved, the banking lobbying group immediately launched a counterattack.
Banking Lobby Group Slams Kraken's Approval for "Limited Purpose" Fed Master Account.
Bitwise: This weekend's attack accelerated the on-chain migration of the financial world
The never-ending market has become a global obsession.
Market Downturn: Which Assets Are Worth Watching?
"Whether it can bring benefits to the holder" is one of the key reference indicators.