Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds
By: crypto news|2025/05/05 18:15:01
0
Share
The Solana Foundation has addressed a critical bug in its privacy-focused token system that, if exploited, could have allowed malicious actors to forge zero-knowledge proofs and perform unauthorized token minting or withdrawals.The flaw was disclosed on April 16 via a GitHub advisory posted by Anza, a Solana development team, along with a working proof-of-concept.Engineers from Anza, Firedancer, and Jito promptly confirmed the issue and began remediation efforts, according to a post-mortem published Saturday.Solana Bug Traced to ZK ElGamal Proof SystemAt the core of the vulnerability was the ZK ElGamal Proof program, which validates zero-knowledge proofs (ZKPs) used in Solana’s Token-22 confidential transfers.These token extensions are designed to enable privacy-preserving transactions by encrypting token balances and using cryptographic proofs to validate transfers.Zero-knowledge proofs allow users to prove the validity of a transaction without revealing sensitive information, such as the amount or recipient address.However, in this instance, a key algebraic component was missing from the hashing process used in the Fiat-Shamir transformation—a common technique that converts interactive proofs into non-interactive ones suitable for blockchain verification.The oversight created a potential backdoor where sophisticated attackers could craft fake proofs that would be mistakenly accepted by the on-chain verifier.Such an exploit could have enabled unauthorized minting of tokens or withdrawals from wallets without permission.Fortunately, the vulnerability did not affect standard SPL tokens or the main Token-2022 logic.Where is the line between esoteric threat to the network of infinite mint risk and roughly 0 risk of application layer bug on contract with roughly 0 usage?Also they didn't secretly upgrade anything they published an update without mentioning the bug and publicly engaged— Block Enthusiast (@BlockEnthusiast) May 5, 2025Private patches were quickly distributed to validator operators on April 17, with a second patch released later that day to address a related issue.External security firms Asymmetric Research, Neodyme, and OtterSec reviewed the fixes.By April 18, the majority of validators had implemented the patch.According to Solana’s post-mortem, there is no evidence the flaw was ever exploited, and all user funds remain safe.Solana Leads Blockchain Revenue Race in Q1 2025Solana has taken the lead among blockchain networks in Q1 2025, outpacing competitors like Ethereum and BNB Chain in total revenue.This marks a major milestone for the high-speed blockchain, driven by a surge in user engagement and an expanding ecosystem.The network’s revenue boost was powered by increased decentralized app (dApp) usage, NFT transactions, and overall on-chain activity.Solana’s scalable architecture and low fees continue to attract developers and users alike, making it a preferred platform for high-volume applications.Its growth was further supported by upgrades, strategic partnerships, and momentum in sectors like DeFi, gaming, and mobile crypto apps.These developments have solidified Solana’s reputation as a user-friendly, high-performance blockchain with a strong outlook for the rest of 2025.The post Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds appeared first on Cryptonews.
You may also like

Key Market Information Discrepancy on March 2nd - A Must-See! | Alpha Morning Report
1. Top News: Last Night's US-Iran Situation Recap, Iranian High-ranking Officials Killed, Over 200 Ships Stranded in the Strait of Hormuz
2. Token Unlock: $ENA

Iran Missile Strike in Dubai: Three Chinese Nationals Tell Their Story 48 Hours Later
The sound is still in the distance, so the days can still go on.

72 Minutes Before Attack, Six Mysterious Accounts Raked in $1.2 Million
These accounts were all registered in February, with most of them making their first deposit within 24 hours before the attack, and they have no other transaction history. Their behavior closely resembles insider trading.

How to Preserve Life and Wealth in Turbulent Times | Bill It Up Memo
In times of chaos, only through diversified allocation and keen observation can one preserve wealth and life in the face of great changes.

I have given up using OpenClaw
Instead of struggling with expensive and unstable AI assistants, it's better to use Claude to create a more stable, cost-effective, and understanding personal system.

WLFI is involved in insider dealings again? The banking license controversy under a $500 million investment
The UAE's investment in World Liberty Financial has intensified concerns about whether it receives special treatment and whether it involves national security issues.

Morning News | Iranian Supreme Leader Khamenei Assassinated; Kalshi to Refund Fees for "Will Khamenei Step Down" Related Market; Bitcoin Spot ETF Sees Net Inflow of $787 Million This Week
Overview of Important Market Events on March 1

The harvesting tactics of the quantitative giant Jane Street
Quantitative giant Jane Street has been accused of manipulating the liquidity and derivatives of markets such as the Indian stock market and Bitcoin, earning billions of dollars in the process.

Cryptocurrency ETF Weekly | Last week, the net inflow for Bitcoin spot ETFs in the U.S. was $787 million; the net inflow for Ethereum spot ETFs in the U.S. was $80.2 million
Top universities like Harvard have started to allocate to Bitcoin ETFs in their endowment funds.

WLFI at it Again? Banking License Controversy Amid $500M Investment
The UAE's investment in World Liberty Financial has heightened concerns over whether it received special treatment and whether national security issues are involved

The Aave civil war escalates, Morpho quietly doubles: Is the lending throne about to change hands?
Wall Street asset management giant Apollo Global Management invested $160 million in Morpho.

Dune Stablecoin Research: The Flow and Demand of a $300 Billion Market
In the dataset, transfers are no longer simply labeled as pure "transaction volume," but are classified as different on-chain activities. This is the difference between "just knowing that $100 trillion has been transferred" and "understanding why it was transferred."

Stripe Annual Letter: New cognitive density is extremely high, especially the 5-level model of "AI + Payments"
Every trend here is affecting everyone's future survival.

Sam Altman's Twenty-Four Hours: The Pentagon said "no" twice, but only one was serious
In Silicon Valley, Altman's sub-12-hour move has a name. It's not called backstabbing, it's called timing.

The US-Iran Conflict Spreads to the Crypto Space: What to Expect in the Market on Monday
The most important industry in the crypto world, only 300 kilometers away from the missile's impact point

Lily Liu, the chair of the Solana Foundation, shouted "Don't waste time on crypto," is the crypto industry really dead?
The interest of the younger generation is shifting from cryptocurrency to the field of artificial intelligence, which coincides with the current phenomenon in the cryptocurrency industry.

The little deer live by the water and grass
Mining companies have never been the most devout believers in Bitcoin. Under the pressures of halving compressing profits, financial reports showing revenue growth without profit increase, and coin prices falling below mining costs, the industry is collectively de-risking.

The world belongs to Chinese people who speak English
The world is vast, and only playing half of it is truly a loss.
Key Market Information Discrepancy on March 2nd - A Must-See! | Alpha Morning Report
1. Top News: Last Night's US-Iran Situation Recap, Iranian High-ranking Officials Killed, Over 200 Ships Stranded in the Strait of Hormuz
2. Token Unlock: $ENA
Iran Missile Strike in Dubai: Three Chinese Nationals Tell Their Story 48 Hours Later
The sound is still in the distance, so the days can still go on.
72 Minutes Before Attack, Six Mysterious Accounts Raked in $1.2 Million
These accounts were all registered in February, with most of them making their first deposit within 24 hours before the attack, and they have no other transaction history. Their behavior closely resembles insider trading.
How to Preserve Life and Wealth in Turbulent Times | Bill It Up Memo
In times of chaos, only through diversified allocation and keen observation can one preserve wealth and life in the face of great changes.
I have given up using OpenClaw
Instead of struggling with expensive and unstable AI assistants, it's better to use Claude to create a more stable, cost-effective, and understanding personal system.
WLFI is involved in insider dealings again? The banking license controversy under a $500 million investment
The UAE's investment in World Liberty Financial has intensified concerns about whether it receives special treatment and whether it involves national security issues.