![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
加密貨幣新聞文章
Solana Foundation Fixes a “zero-day” Bug That Gave Attackers Unlimited Token Minting Capabilities
2025/05/06 03:30
Solana Foundation has confirmed fixing a “zero-day” bug that gave attackers unlimited token minting capabilities and the ability to withdraw tokens from user accounts. The issue, discovered on April 16, was resolved within two days after validators rapidly deployed two critical patches across the network.
According to the Foundation’s May 3 post-mortem report, the bug affected the ZK ElGamal Proof program, which is used to validate zero-knowledge proofs linked to confidential transfers in Token-2022, now called Token-22. The flaw emerged from missing alegbraic components in the Fiat-Shamir Transformation, which is used for cryptographic randomness, making it possible to craft forged proofs.
Despite the seriousness of the vulnerability, Solana Foundation said that there were no known exploits or loss of funds. The patches were implemented by a group of development teams, including Anza, Firedancer, and Jito, with support from security researchers at OtterSec, Asymmetric Research, and Neodyme.
Solana Validators Privately Coordinated to Deploy Fix
Before disclosing the vulnerability, Solana Foundation contacted validators to coordinate the fixing process privately. Through this method, validators were able to deploy the solution quickly. However, this move sparked renewed concerns about decentralization and transparency.
Solana co-founder Anatoly Yakovenko responded to the criticism on X, saying that similar coordination happens on Ethereum too. According to him, major Ethereum validators, including Binance, Coinbase, Kraken, and Lido, could quickly agree to implement urgent security patches whenever needed.
“Bro, it’s the same people to get to 70% on ethereum. All the lido validators (chorus one, p2p, etc..) binance, coinbase, and kraken. If geth needs to push a patch, I’ll be happy to coordinate for them.”
However, critics questioned how the Solana Foundation contacted all validators in the network. Moreover, users expressed concerns about censorship or rollback through off-chain coordination, referencing prior similar responses to undisclosed bugs.
Confidential Transfer Feature Had Limited Adoption
Technically, the identified vulnerability posed a threat to token forgery and theft, but its practical impact remained limited. The affected feature, known as confidential transfer, was minimally implemented throughout the network by third parties.
Despite speculations about its involvement, Paxos said that it’s not operating the confidential transfer system. A spokesperson stated that the service is currently not live on any Paxos-issued stablecoins.
Related: How Browser Wallet Permissions Were Exploited in the Latest LinkedIn Job Offer Scam
Meanwhile, Ethereum community member Ryan Berckmans argued that Solana remains vulnerable due to its reliance on a single production-ready client, Agave. In contrast, he highlighted Ethereum’s client diversity, with the leading client, Geth, holding 41% market share, fostering protocol resilience.
Solana plans to launch its new network client, Firedancer, in the upcoming months to solve this problem. According to the Foundation, coordinated emergency patches are a requirement for network security and do not indicate centralization.
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 以太坊,交易量和SEC的積分:導航監管景觀
- 2025-08-06 22:05:31
- 以太坊的交易量在SEC Staking指導中湧現,提出了樂觀和監管問題。這對Defi和Crypto的未來意味著什麼?
-
- 加密市場的嗡嗡聲:證明是共同案例,二元列表令牌
- 2025-08-06 22:00:30
- 加密市場將新的動態視為簡潔的象徵性收益在Coinbase和Binance等主要交易所的列表之後。是什麼推動了這一激增?
-
- 巴西,比特幣,聽證日期:巴西要擁抱比特幣嗎?
- 2025-08-06 20:00:10
- 巴西代表會議將於2025年8月20日舉行公開聽證會,討論在其國家儲備中增加比特幣。這可以改變遊戲規則嗎?
-
-
- Wewake Finance:這是您一直在等待的加密ROI機會嗎?
- 2025-08-06 20:00:00
- 探索Wewake Finance對Web3可訪問性的創新方法及其在不斷發展的加密景觀中的高ROI潛力。
-
- Pancakeswap,美國股票和永久合同:Defi的新邊界
- 2025-08-06 19:53:39
- Pancakeswap潛入美國的股票代幣永久合同,與傳統的金融架起融合。這是分散交易的未來嗎?
-
-
- 加密,東盟和菲律賓:Web3的後起之秀?
- 2025-08-06 19:51:28
- 菲律賓將自己定位為東盟的Web3中心。即將舉行的事件和像特朗普這樣的主要參與者會加速加密貨幣的採用?
-