Inside Solana’s Secret Patch for Confidential Token Exploits
By: cryptosheadlines|2025/05/05 08:45:01
0
Share
Airdrop Is Live CaryptosHeadlines Media Has Launched Its Native Token CHT. Airdrop Is Live For Everyone, Claim Instant 5000 CHT Tokens Worth Of $50 USDT. Join the Airdrop at the official website, CryptosHeadlinesToken.com – Advertisement –A Solana ZK-Proof flaw allowed forging confidential token transfers; patches rolled out within 48 hours to prevent exploits.Engineers fixed unhashed data gaps in Solana’s ZK ElGamal program, stopping unauthorized mints or withdrawals.In April 2025, a security report submitted to the Anza GitHub repository outlined a potential flaw in Solana’s ZK ElGamal Proof program, a component tied to its confidential token system. The report included a proof of concept demonstrating how an attacker could create invalid proofs that the program might accept. Engineers from Anza, Firedancer, and Jito confirmed the issue within hours, finding that unhashed data in the program’s verification process could allow forged transactions.No exploits were detected before the patchBy the evening of April 17, Solana Foundation and Jito teams began privately distributing a fix to validator operators. Later that night, a second related flaw was identified, prompting another update. Both patches underwent review by security firms Asymmetric Research, Neodyme, and OtterSec before reaching validators. By April 18, over two-thirds of the network’s validators had implemented the fixes, ensuring the blockchain’s security. A public announcement followed that evening, confirming the cluster’s stability.Solana’s Token-2022 standard, which supports confidential transfers, relies on two components: the Token-2022 program for managing tokens and the ZK ElGamal Proof program for verifying encrypted balances. The latter uses a cryptographic method called the Fiat-Shamir Transformation to convert interactive proofs into non-interactive ones. This process requires hashing all mathematical inputs to generate verification parameters.The vulnerability stemmed from incomplete hashing during proof verification. Attackers could exploit this gap to fabricate transactions, such as minting tokens without authorization or withdrawing from protected accounts. The patch, released in versions Agave v2.1.21/Jito-Solana v2.1.21-jito and later iterations, corrected the hashing process. Firedancer’s update (v0.411.20121) incorporated the same adjustments.No changes were needed for the Token-2022 program itself, as the issue was isolated to the proof system. Security audits conducted prior to the incident and post-patch reviews confirmed the solution’s effectiveness.The coordinated response prevented disruption to Solana’s network. Validators adopted the updates swiftly, and no funds were compromised. While the incident underscores the challenges of securing complex cryptographic systems, the resolution highlights the effectiveness of collaborative problem-solving in decentralized environments.For users of Token-2022 confidential tokens, the takeaway is clear: the system remains secure, but vigilance is part of the process. Developers continue to prioritize proactive measures, ensuring that potential risks are addressed before they materialize.Source: SOL/TradingviewAs of now, Solana (SOL) is trading at $146.27, showing a -0.88% decrease in the last 24 hours and a -2.18% decline over the past 7 days. Its market capitalization stands at approximately $75.77 billion, placing it firmly in the top 10 cryptocurrencies. With a circulating supply of over 520 million tokens, SOL continues to be one of the leading Layer 1 blockchains focused on high-speed, low-cost transactions.From a technical standpoint, SOL remains bullish over the medium-term with gains of 18.6% over the last 30 days, though recent corrections signal possible consolidation. Its trading volume in the past 24 hours is around $1.7 billion, slightly lower, which may indicate some cooling in short-term momentum. Key resistance remains near $150, while strong support holds around the $140 mark.Based on current chart patterns and market sentiment, ETHNews predict SOL may reach $162.50 within the next 7–10 days, assuming no major market disruption. However, a failure to hold $140 support could bring it down to $134 briefly.Source link
You may also like

Musk Poached Aave App's Web3 Prodigy
Aesthetic is a gift.

The Petro Order is Cracking. What Comes Next for the Middle East?
Ground War Begins, or Deterrence Takes Hold

ETF Fund Inflows Emerging, What's Still Missing for BTC to Fully Recover?
The market is entering a crucial phase of equilibrium.

Forbes Special Report: The Embrace of AI Agents in the Cryptocurrency Industry
AI agents are becoming the true native users of cryptocurrency; they do not need a beautiful interface, just a wallet and a payment track. This wave of "machine commerce" may be the most rational narrative in the crypto industry for years, or it may just be another round of hype in a new bottle.

Bitpanda, Vision Web3 Foundation, and Optimism Partner to Onboard European Financial Institutions to the Global Blockchain Economy
Vision Chain aims to address the long-standing infrastructure bottlenecks in the European financial sector

What will the early Hyperliquid prediction market look like?
Unleash the Imagination Space of On-chain Finance

Overseas VC's Two-Week Trip to China AI Leaves Them in Awe of Shenzhen Hardware
Delphi Labs founder's two-week deep dive into China's AI ecosystem: More bullish on hardware than expected, more bearish on software than expected, and observations on Chinese founders that flipped his prior beliefs.

Was CZ Also Rug Pulled? BNB Treasury CEA Industries Control Battle
CEA Industries' mNAV drops to 0.68, YZi Labs personally steps in to clean up the mess

A transaction in 7 seconds, earning tens of millions of dollars, he's seen as the "cancer of meme coins."
The belief that "Day Trading Shitcoins is the Only Way to Make Money" has become their go-to strategy.

Bittensor Ecosystem Token SN Surges 5x in March, What's Behind Richard Heart's One-Liner?
What did Andrew Ng say? Did he say anything? Is Distributed AI Training Feasible?

The economy is entering a new cycle, how can the average person prepare?
The key is not how much you earn, but whether you have cash flow, low leverage, and the ability to earn consistently

Access Binance Alpha Box: Sigma.Money to Launch BNB Chain Ecosystem Yield Farming Gateway
Sigma.Money's innovation is now translating into tangible market momentum.

Kimi, Chip, and Bean come together for a Crypto Hackathon: What did AI developers build on Monad?
Monad Ecosystem AI Deployment, More Than Just a Hackathon.

How to Trade Crypto on Mobile Browser & Win LALIGA Tickets (2026 Guide)
Discover how AI automation, natural language trading, and mobile browser trading platforms are shaping automated trading in 2026. Join the WEEX live trading event for early access and rewards like LALIGA VIP tickets.

Connecting encryption, TradFi, and payments, is Gate completing the final puzzle of the "super APP"?
Why is it said that TradFi is not a short-term narrative?

a16z Crypto Operating Partner: Wall Street is undergoing its biggest infrastructure upgrade in 30 years
What is currently happening is the largest infrastructure upgrade in the capital market since the rise of electronic trading thirty years ago.

a16z Crypto's latest research: What is the key to the large-scale application of DeFi?
The widespread adoption of on-chain financial applications still faces an invisible barrier: the lack of transaction order certainty. Under a single leader architecture, nodes can delay, censor, or even front-run user transactions, thus completely distorting the game among market makers, bidders, an...

Founder of Delphi Labs: My observations and feelings about the AI ecosystem in China in two weeks
Delphi Labs co-founded a deep observation of China's AI ecosystem: hardware manufacturing is quietly winning the global war at an astonishing speed, but the software sector is mired in an overvaluation bubble and the homogenization of founders.
Musk Poached Aave App's Web3 Prodigy
Aesthetic is a gift.
The Petro Order is Cracking. What Comes Next for the Middle East?
Ground War Begins, or Deterrence Takes Hold
ETF Fund Inflows Emerging, What's Still Missing for BTC to Fully Recover?
The market is entering a crucial phase of equilibrium.
Forbes Special Report: The Embrace of AI Agents in the Cryptocurrency Industry
AI agents are becoming the true native users of cryptocurrency; they do not need a beautiful interface, just a wallet and a payment track. This wave of "machine commerce" may be the most rational narrative in the crypto industry for years, or it may just be another round of hype in a new bottle.
Bitpanda, Vision Web3 Foundation, and Optimism Partner to Onboard European Financial Institutions to the Global Blockchain Economy
Vision Chain aims to address the long-standing infrastructure bottlenecks in the European financial sector
What will the early Hyperliquid prediction market look like?
Unleash the Imagination Space of On-chain Finance
