![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
加密貨幣新聞文章
Critical Security Flaw in Solana Labs' Token-2022 and ZK ElGamal Proof Programs
2025/05/05 19:16
A critical security flaw affecting the Token-2022 and ZK ElGamal Proof programs of Solana was identified on April 16, 2025, by security researchers.
The vulnerability, which theoretically allowed for unlimited minting of confidential Token-22 tokens, an extension based on zero-knowledge disclosure proof (zk-proofs), has been patched, according to a post-mortem report by Solana Foundation.
The issue stemmed from a hashing error in certain mathematical components during the Fiat-Shamir transformation, weakening the cryptographic verification of proofs and potentially opening the door for malicious actors to forge proofs and mint tokens at will.
However, no exploitation was detected before the bug was fixed, and development teams responded quickly, deploying a patch within 48 hours through a coordinated validator update.
Despite this prompt response, the handling of this incident has drawn harsh criticisms within the crypto community, with some highlighting the lack of transparency from the Solana Foundation in coordinating with validators.
“Why does one entity have all validators’ contact details? What discussions take place in these private channels?” questioned a Curve Finance contributor, fearing potential censorship or an orchestrated rollback of the network.
Solana Labs co-founder, Anatoly Yakovenko, tried to downplay the situation by comparing this emergency to the coordination capability of key Ethereum players in case of critical bugs. But this analogy was strongly contested by a prominent Ethereum community member, Ryan Berckmans.
According to Berckmans, the fundamental difference lies in the diversity of clients. While Geth represents a maximum of 41% of the Ethereum market, Solana currently has only one fully operational client: Agave.
People are missing the important points in this Solana emergency fork situation
1) Eth has client diversity and a protocol spec steered by a meaningful research community.
The most popular eth client, geth, has at most 41% market share.
Sol has one prod client (just one; don't integrate yet!) and no real protocol spec research community.
2) This isn't an anomaly. It's a critical bug in a core crypto primitive used across many chains.
According to Berckmans, the integrality of Agave makes any bug a direct vulnerability of the Solana protocol, rendering the separation between application and protocol nearly meaningless.
“On Solana, a bug in the sole available client is, de facto, a protocol bug. Modifying the client is equivalent to modifying the protocol. There is no functional separation,” he lamented.
However, Solana Foundation is banking on the arrival of the alternative client Firedancer in 2025, aimed at enhancing network resilience and robustness. But according to Berckmans, Solana would need at least three distinct clients to claim true protocol-level decentralization.
The Solana security flaw highlights the unique challenges of centralized-governance blockchains, a major concern for French and European stakeholders – regulators, investors, or developers.
As Europe refines the MiCA regulatory framework, the robustness of the underlying infrastructure of issued tokens becomes critically important. This incident could thus serve as a lesson for future certifications or criteria for integrating digital asset projects.
While Solana demonstrated exemplary responsiveness, the method employed raises legitimate concerns about the network’s technical governance. Client diversity, transparency in incident management, and the ability to weather crises without compromising neutrality are now crucial analytical criteria.
If you can call up the validator nodes to coordinate a critical zero day bug fix, you can call them up to do whatever you want. This is NOT the decentralisation we should be striving for.
And CT is celebrating this as "security is important" #Solana 🙄
The Solana security flaw is a wake-up call: the pursuit of performance and innovation cannot come at the expense of fundamental decentralization principles. An important reminder for the entire crypto ecosystem, at a time when issues of trust and security are more crucial than ever.
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 種子短語,自我監護和責任:您真的是自己的銀行嗎?
- 2025-06-21 04:25:11
- 探索加密貨幣中自我顧客的風險和回報,重點關注種子短語及其介紹的責任。是真的“成為您自己的銀行”還是只是在改變負擔?
-
- 比特幣需求乾燥:資本退出和市場猶豫不決
- 2025-06-21 04:25:11
- 比特幣的價格行動停滯不前,因為需求步履蹣跚和退出資本,使市場處於猶豫不決的狀態。這只是下一次飛躍之前的呼吸,還是更深層麻煩的跡象?
-
-
- 比特幣,量子計算機和密碼學:紐約市量詞後景觀
- 2025-06-21 04:45:12
- 探索比特幣,量子計算機和加密的交集:評估量子世界中數字資產的威脅,遷移策略和未來。
-
-
- 固定以太,公司加密和財務收養:紐約分鐘
- 2025-06-21 02:45:13
- 潛入湯匙的以太,公司加密貨幣和財務採用的世界。了解趨勢,見解及其對金融的未來意味著什麼。
-
-
- Reddit,WorldCoin和Iris掃描:用戶驗證的新時代?
- 2025-06-21 02:45:13
- 探索Reddit潛在地使用WorldCoin的虹膜掃描ORB,以在對機器人和AI的關注點上增加。
-
- 投資者資金,比特幣和購買技巧:導航加密貨幣景觀
- 2025-06-21 02:50:12
- 探索投資者基金采用的創新策略來獲取比特幣,包括“增生稀釋”和其他購買技巧在當今動蕩的加密市場中。