![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
加密貨幣新聞文章
Solana Foundation Fixes a “zero-day” Bug That Gave Attackers Unlimited Token Minting Capabilities
2025/05/06 03:30
Solana Foundation has confirmed fixing a “zero-day” bug that gave attackers unlimited token minting capabilities and the ability to withdraw tokens from user accounts. The issue, discovered on April 16, was resolved within two days after validators rapidly deployed two critical patches across the network.
According to the Foundation’s May 3 post-mortem report, the bug affected the ZK ElGamal Proof program, which is used to validate zero-knowledge proofs linked to confidential transfers in Token-2022, now called Token-22. The flaw emerged from missing alegbraic components in the Fiat-Shamir Transformation, which is used for cryptographic randomness, making it possible to craft forged proofs.
Despite the seriousness of the vulnerability, Solana Foundation said that there were no known exploits or loss of funds. The patches were implemented by a group of development teams, including Anza, Firedancer, and Jito, with support from security researchers at OtterSec, Asymmetric Research, and Neodyme.
Solana Validators Privately Coordinated to Deploy Fix
Before disclosing the vulnerability, Solana Foundation contacted validators to coordinate the fixing process privately. Through this method, validators were able to deploy the solution quickly. However, this move sparked renewed concerns about decentralization and transparency.
Solana co-founder Anatoly Yakovenko responded to the criticism on X, saying that similar coordination happens on Ethereum too. According to him, major Ethereum validators, including Binance, Coinbase, Kraken, and Lido, could quickly agree to implement urgent security patches whenever needed.
“Bro, it’s the same people to get to 70% on ethereum. All the lido validators (chorus one, p2p, etc..) binance, coinbase, and kraken. If geth needs to push a patch, I’ll be happy to coordinate for them.”
However, critics questioned how the Solana Foundation contacted all validators in the network. Moreover, users expressed concerns about censorship or rollback through off-chain coordination, referencing prior similar responses to undisclosed bugs.
Confidential Transfer Feature Had Limited Adoption
Technically, the identified vulnerability posed a threat to token forgery and theft, but its practical impact remained limited. The affected feature, known as confidential transfer, was minimally implemented throughout the network by third parties.
Despite speculations about its involvement, Paxos said that it’s not operating the confidential transfer system. A spokesperson stated that the service is currently not live on any Paxos-issued stablecoins.
Related: How Browser Wallet Permissions Were Exploited in the Latest LinkedIn Job Offer Scam
Meanwhile, Ethereum community member Ryan Berckmans argued that Solana remains vulnerable due to its reliance on a single production-ready client, Agave. In contrast, he highlighted Ethereum’s client diversity, with the leading client, Geth, holding 41% market share, fostering protocol resilience.
Solana plans to launch its new network client, Firedancer, in the upcoming months to solve this problem. According to the Foundation, coordinated emergency patches are a requirement for network security and do not indicate centralization.
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
-
- XRP價格:即將到來的市場突破?分析預測
- 2025-06-21 16:25:12
- XRP是否在重大突破的邊緣?檢查最新的市場趨勢,專家分析和價格預測,以確定XRP的潛在軌跡。
-
-
-
-
-
- Bonk價格檢查:支持區和大膽的2025預測
- 2025-06-21 14:45:13
- Bonk緊緊掛在關鍵區域,分析師著眼於潛在的突破。 2025是否會將模因硬幣帶回以前的榮耀?查出!
-
- 懲罰者硬幣:100倍的潛力還是SEC警告標誌?
- 2025-06-21 15:25:12
- 尼日利亞的SEC警告說,懲罰者硬幣($ PUN)面臨審查,與其吹捧的100倍潛力和創新功能形成鮮明對比。
-
- IOTA價格下跌:導航低迷和發現機會
- 2025-06-21 15:25:12
- IOTA面臨價格壓力。該博客分析了下降和潛在的恢復信號背後的因素,為貿易商和長期持有人提供了見解。