![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
Nachrichtenartikel zu Kryptowährungen
The Solana Foundation has disclosed and patched a zero-day vulnerability
May 05, 2025 at 05:00 pm
The Solana Foundation has disclosed and patched a zero-day vulnerability that could have allowed attackers to mint confidential tokens and withdraw them from unsuspecting users’ accounts.
The flaw, which was silently resolved before any known exploit occurred, has swiftly sparked heated debates around Solana’s network decentralization as several key contributors, including Anza, Firedancer, Jito, Asymmetric Research, Neodyme, and OtterSec, came together to coordinate the patching process.
According to a May 3 post-mortem from the Solana Foundation, the vulnerability was first identified on April 16 and affected Solana’s privacy-focused "Token-22 confidential tokens." These tokens rely on zero-knowledge proofs (ZKPs) to ensure the privacy of transfers, a feature designed to enable advanced and confidential token functionalities within the Solana ecosystem.
On April 16, 2025, the Solana Foundation discovered a zero-day vulnerability in the Token-2022 standard's confidential transfers feature, which could have allowed attackers to forge zero-knowledge proofs to mint unlimited tokens or steal user assets. The Foundation privately…
The security gap originated in the Token-2022 and ZK ElGamal Proof programs, where a cryptographic flaw in the Fiat-Shamir Transformation process had implications for forging proofs. It occurred because certain algebraic components were not properly hashed, undermining the integrity of the proof verification mechanism.
In essence, the flaw might have enabled malicious actors to simulate valid balances and mint confidential tokens—an alarming loophole that, had it been exploited, could have seen batches of tokens spawn out of thin air.
Despite the critical nature of the vulnerability, no funds were lost, and a supermajority of validators had already adopted the patched version within two days.
Solana Patch Sparks Centralization Fears
The rapid behind-the-scenes patching process has nevertheless raised eyebrows among decentralization purists.
A contributor from Curve Finance sparked the discussion by inquiring about the Foundation's ability to swiftly contact validators and whether this level of influence undermines SOL's claims of being a decentralized network.
The concern: such close coordination could facilitate censorship or even orchestrated rollbacks, hallmarks of centralized control.
This seems like a massive vulnerability to have been discovered so quickly. Is there a reason why the snapshot on April 15th was used instead of the genesis snapshot? Wouldn't that have huge implications for liquidity on the chain?
Solana Labs CEO Anatoly Yakovenko responded by highlighting that Ethereum validators, many operated by large staking providers like Lido, Binance, Coinbase, and Kraken, could coordinate similarly in a severe emergency.
"If geth needs to push a patch, I’ll be happy to coordinate for them. We can ping them on the relevant Discord channels or email,” Yakovenko stated.
But not everyone agrees with the comparison.
Solana One Client Risk Exposed
A member of the Ethereum community, Ryan Berckmans, countered that Ethereum's client diversity serves as a safeguard against the kind of single-point-of-failure risks posed by SOL. He noted that Geth, Ethereum's dominant client, holds no more than 41% market share, while SOL currently operates with just one production-ready client, Agave.
"This means that a zero-day bug in the single Solana client is de facto a protocol bug. Change the single client program, change the protocol itself. This is a huge difference," Berckmans argued.
Solana's roadmap offers a partial answer. The highly anticipated Firedancer client, developed in collaboration with Jump Crypto and expected to launch in the coming months, promises enhanced performance and redundancy.
Still, as Berckmans pointed out, true decentralization at the client level may require at least three independent clients, a goal that Solana has yet to achieve.
While the vulnerability was patched swiftly before any real damage occurred, the incident highlights a growing tension in the blockchain world: the trade-off between security responsiveness and decentralization.
Solana's ability to act quickly in the face of a zero-day flaw is commendable, but it has also spotlighted its centralized levers of control.
As Solana continues to evolve with Firedancer on the horizon and more zero-knowledge capabilities in development, the community will be watching closely to see whether the network can strike a sustainable balance between performance, privacy, and decentralization.
Haftungsausschluss:info@kdj.com
Die bereitgestellten Informationen stellen keine Handelsberatung dar. kdj.com übernimmt keine Verantwortung für Investitionen, die auf der Grundlage der in diesem Artikel bereitgestellten Informationen getätigt werden. Kryptowährungen sind sehr volatil und es wird dringend empfohlen, nach gründlicher Recherche mit Vorsicht zu investieren!
Wenn Sie glauben, dass der auf dieser Website verwendete Inhalt Ihr Urheberrecht verletzt, kontaktieren Sie uns bitte umgehend (info@kdj.com) und wir werden ihn umgehend löschen.
-
-
- Beatrix Potter 50p -Münzen bei eBay: Ein Kollektorhandbuch für Wert und Seltenheit
- Aug 06, 2025 at 08:00 am
- Tauchen Sie in die Welt von Beatrix Potter 50p Münzen und ihren Wert bei eBay ein. Entdecken Sie die Schlüsselfaktoren, die ihren Wert beeinflussen und wie Sie einen wertvollen Fund erkennen können.
-
-
-
- Executive Order vs. Finanzinstitutionen: Ist die politische Voreingenommenheit die neue Normalität?
- Aug 06, 2025 at 07:36 am
- Tritt die Regierung ein, um Konservative und Krypto vor "Debanking" zu schützen? Eine Exekutivverordnung, die sich an die mutmaßliche politische Voreingenommenheit in Finanzinstitutionen richtet, könnte die Dinge aufrütteln.
-
-
- Metamask, MMUSD und Ethereum: Eine New Yorker Minute zu Defis neuesten Schritten
- Aug 06, 2025 at 07:27 am
- Das MMUSD Stablecoin von Metamask, der auf Ethereum basiert, zielt darauf ab, Defi neu zu definieren. Mit Stripe & Aave befasst sich die Stabilität und Benutzerfreundlichkeit. Hier ist der Tiefstall.
-
-
- Die Strategie von Ripple, den XRP -Preis und den potenziellen Schub von Litecoin: Was ist der Deal?
- Aug 06, 2025 at 07:09 am
- Tauchen Sie in die neuesten Bankenbewegungen von Ripple, XRP -Preisvorhersagen und Litecoin's Bullish Outlook. Außerdem ein Blick auf den potenziellen Anstieg von Magacoin Finance.