Close Menu
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Cryphedge.com
Home » Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds
Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds

Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds

May 5, 20253 Mins ReadNo Comments Altcoins
Share
Facebook Twitter LinkedIn Pinterest Email

The Solana Foundation has addressed a critical bug in its privacy-focused token system that, if exploited, could have allowed malicious actors to forge zero-knowledge proofs and perform unauthorized token minting or withdrawals.

The flaw was disclosed on April 16 via a GitHub advisory posted by Anza, a Solana development team, along with a working proof-of-concept.

Engineers from Anza, Firedancer, and Jito promptly confirmed the issue and began remediation efforts, according to a post-mortem published Saturday.

Solana Bug Traced to ZK ElGamal Proof System

At the core of the vulnerability was the ZK ElGamal Proof program, which validates zero-knowledge proofs (ZKPs) used in Solana’s Token-22 confidential transfers.

These token extensions are designed to enable privacy-preserving transactions by encrypting token balances and using cryptographic proofs to validate transfers.

Zero-knowledge proofs allow users to prove the validity of a transaction without revealing sensitive information, such as the amount or recipient address.

However, in this instance, a key algebraic component was missing from the hashing process used in the Fiat-Shamir transformation—a common technique that converts interactive proofs into non-interactive ones suitable for blockchain verification.

The oversight created a potential backdoor where sophisticated attackers could craft fake proofs that would be mistakenly accepted by the on-chain verifier.

Such an exploit could have enabled unauthorized minting of tokens or withdrawals from wallets without permission.

Fortunately, the vulnerability did not affect standard SPL tokens or the main Token-2022 logic.

Where is the line between esoteric threat to the network of infinite mint risk and roughly 0 risk of application layer bug on contract with roughly 0 usage?

Also they didn't secretly upgrade anything they published an update without mentioning the bug and publicly engaged

— Block Enthusiast 🌱🌪🏴‍☠️ (@BlockEnthusiast) May 5, 2025

Private patches were quickly distributed to validator operators on April 17, with a second patch released later that day to address a related issue.

External security firms Asymmetric Research, Neodyme, and OtterSec reviewed the fixes.

By April 18, the majority of validators had implemented the patch.

According to Solana’s post-mortem, there is no evidence the flaw was ever exploited, and all user funds remain safe.

Solana Leads Blockchain Revenue Race in Q1 2025

Solana has taken the lead among blockchain networks in Q1 2025, outpacing competitors like Ethereum and BNB Chain in total revenue.

This marks a major milestone for the high-speed blockchain, driven by a surge in user engagement and an expanding ecosystem.

The network’s revenue boost was powered by increased decentralized app (dApp) usage, NFT transactions, and overall on-chain activity.

Solana’s scalable architecture and low fees continue to attract developers and users alike, making it a preferred platform for high-volume applications.

Its growth was further supported by upgrades, strategic partnerships, and momentum in sectors like DeFi, gaming, and mobile crypto apps.

These developments have solidified Solana’s reputation as a user-friendly, high-performance blockchain with a strong outlook for the rest of 2025.

The post Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds appeared first on Cryptonews.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
cryphedge

Related Posts

Web3 Ai Leads With $777K Giveaway

May 21, 2025

215% Increase Could Be On The Cards For DOGE

May 21, 2025

Binance Pay Integrates with Brazil’s Pix for Instant Crypto Payments Across LATAM’s Largest Market

May 21, 2025

P2P.org Give Solana Staking Shot In The Arm With Liquidity Vault Supported By Kamino Finance & Re7 Labs

May 21, 2025
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

BPI releases policy manifesto urging US to lead in Bitcoin infrastructure

May 21, 2025

SUI Flips XRP in Institutional Inflows

May 21, 2025

Web3 Ai Leads With $777K Giveaway

May 21, 2025

OnRe, Backed by Ethena, Solana Ventures, and RockawayX Launches Structured Yield Product Combining Real-World Stability and On-Chain Upside

May 21, 2025
About

cryphedge is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news, regulation, trading, crypto scams and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

RTFKT NFTs Disappear After Cloudflare Glitch Disrupts Image Hosting

April 25, 2025

The Race for ETF Approval Begins: It’s Not the Time to be Bearish on XRP & Solana—But Here’s a Twist

February 7, 2025

Bitcoin (BTC) Defies Market Sentiment, Holds Strong Above 200-Day Moving Average

March 27, 2025
Subscribe
Please enable JavaScript in your browser to complete this form.
Loading
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$109,662.002.75%
  • ethereumEthereum(ETH)$2,573.041.78%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$2.402.00%
  • binancecoinBNB(BNB)$675.203.87%
  • solanaSolana(SOL)$174.193.61%
  • usd-coinUSDC(USDC)$1.000.00%
  • dogecoinDogecoin(DOGE)$0.2365674.65%
  • cardanoCardano(ADA)$0.774.09%
  • tronTRON(TRX)$0.268180-0.31%
  • staked-etherLido Staked Ether(STETH)$2,572.431.93%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$109,345.002.80%
  • suiSui(SUI)$3.952.36%
  • Wrapped stETHWrapped stETH(WSTETH)$3,091.511.71%
  • chainlinkChainlink(LINK)$16.183.19%
  • avalanche-2Avalanche(AVAX)$23.363.63%
  • HyperliquidHyperliquid(HYPE)$28.397.44%
  • stellarStellar(XLM)$0.2946102.56%
  • shiba-inuShiba Inu(SHIB)$0.0000152.51%
  • hedera-hashgraphHedera(HBAR)$0.1983702.01%
  • bitcoin-cashBitcoin Cash(BCH)$412.975.11%
  • leo-tokenLEO Token(LEO)$8.871.00%
  • the-open-networkToncoin(TON)$3.111.22%
  • litecoinLitecoin(LTC)$97.643.35%
  • polkadotPolkadot(DOT)$4.771.81%
  • moneroMonero(XMR)$391.3111.64%
  • USDSUSDS(USDS)$1.000.00%
  • WETHWETH(WETH)$2,569.691.87%
  • Wrapped eETHWrapped eETH(WEETH)$2,742.821.78%
  • bitget-tokenBitget Token(BGB)$5.231.71%
  • Pi NetworkPi Network(PI)$0.8410.78%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.04%
  • pepePepe(PEPE)$0.0000144.23%
  • Ethena USDeEthena USDe(USDE)$1.000.03%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$109,581.002.74%
  • whitebitWhiteBIT Coin(WBT)$30.10-0.28%
  • BittensorBittensor(TAO)$451.669.22%
  • uniswapUniswap(UNI)$6.355.26%
  • aaveAave(AAVE)$249.91-3.17%
  • daiDai(DAI)$1.000.01%
  • nearNEAR Protocol(NEAR)$2.893.01%
  • aptosAptos(APT)$5.313.37%
  • okbOKB(OKB)$52.510.60%
  • Jito Staked SOLJito Staked SOL(JITOSOL)$209.523.57%
  • OndoOndo(ONDO)$0.994.52%
  • kaspaKaspa(KAS)$0.1120731.81%
  • crypto-com-chainCronos(CRO)$0.0980371.67%
  • ethereum-classicEthereum Classic(ETC)$19.164.14%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Official TrumpOfficial Trump(TRUMP)$14.471.49%
  • Tokenize XchangeTokenize Xchange(TKX)$36.01-0.13%
  • internet-computerInternet Computer(ICP)$5.402.82%
  • gatechain-tokenGate(GT)$21.901.85%
  • vechainVeChain(VET)$0.0294103.37%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.170.00%
  • render-tokenRender(RENDER)$4.813.60%
  • mantleMantle(MNT)$0.74-0.48%
  • EthenaEthena(ENA)$0.4073797.43%
  • sUSDSsUSDS(SUSDS)$1.050.02%
  • cosmosCosmos Hub(ATOM)$5.013.70%
  • polygon-ecosystem-tokenPOL (ex-MATIC)(POL)$0.2440485.64%
  • USD1USD1(USD1)$1.00-0.11%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.828.38%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$109,622.003.32%
  • arbitrumArbitrum(ARB)$0.4142505.07%
  • algorandAlgorand(ALGO)$0.2314463.33%
  • filecoinFilecoin(FIL)$2.984.35%
  • fasttokenFasttoken(FTN)$4.420.49%
  • worldcoin-wldWorldcoin(WLD)$1.218.84%
  • CelestiaCelestia(TIA)$2.66-0.46%
  • Jupiter Perpetuals Liquidity Provider TokenJupiter Perpetuals Liquidity Provider Token(JLP)$4.631.83%
  • Sonic (prev. FTM)Sonic (prev. FTM)(S)$0.512.16%
  • bonkBonk(BONK)$0.0000214.24%
  • Binance-Peg WETHBinance-Peg WETH(WETH)$2,572.471.78%
  • first-digital-usdFirst Digital USD(FDUSD)$1.000.32%
  • JupiterJupiter(JUP)$0.534.86%
  • Binance Staked SOLBinance Staked SOL(BNSOL)$183.183.50%
  • quant-networkQuant(QNT)$98.821.64%
  • blockstackStacks(STX)$0.947.45%
  • FartcoinFartcoin(FARTCOIN)$1.4310.31%
  • kucoin-sharesKuCoin(KCS)$11.35-2.92%
  • Kelp DAO Restaked ETHKelp DAO Restaked ETH(RSETH)$2,676.171.53%
  • Virtuals ProtocolVirtuals Protocol(VIRTUAL)$2.002.22%
  • nexoNEXO(NEXO)$1.27-0.04%
  • flare-networksFlare(FLR)$0.0191571.20%
  • StoryStory(IP)$4.48-0.69%
  • immutable-xImmutable(IMX)$0.684.32%
  • optimismOptimism(OP)$0.754.28%
  • sei-networkSei(SEI)$0.2326373.82%
  • injective-protocolInjective(INJ)$12.604.23%
  • rocket-pool-ethRocket Pool ETH(RETH)$2,918.581.74%
  • makerMaker(MKR)$1,752.301.65%
  • USDT0USDT0(USDT0)$1.000.09%
  • eosEOS(EOS)$0.76-3.72%
  • xdce-crowd-saleXDC Network(XDC)$0.0714111.51%
  • dogwifhatdogwifhat(WIF)$1.1212.85%
  • the-graphThe Graph(GRT)$0.1157364.02%
  • Solv Protocol BTCSolv Protocol BTC(SOLVBTC)$109,552.002.91%
  • curve-dao-tokenCurve DAO(CRV)$0.755.57%
  • flokiFLOKI(FLOKI)$0.0001034.37%