![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
加密货币新闻
Critical Security Flaw in Solana Labs' Token-2022 and ZK ElGamal Proof Programs
2025/05/05 19:16
A critical security flaw affecting the Token-2022 and ZK ElGamal Proof programs of Solana was identified on April 16, 2025, by security researchers.
The vulnerability, which theoretically allowed for unlimited minting of confidential Token-22 tokens, an extension based on zero-knowledge disclosure proof (zk-proofs), has been patched, according to a post-mortem report by Solana Foundation.
The issue stemmed from a hashing error in certain mathematical components during the Fiat-Shamir transformation, weakening the cryptographic verification of proofs and potentially opening the door for malicious actors to forge proofs and mint tokens at will.
However, no exploitation was detected before the bug was fixed, and development teams responded quickly, deploying a patch within 48 hours through a coordinated validator update.
Despite this prompt response, the handling of this incident has drawn harsh criticisms within the crypto community, with some highlighting the lack of transparency from the Solana Foundation in coordinating with validators.
“Why does one entity have all validators’ contact details? What discussions take place in these private channels?” questioned a Curve Finance contributor, fearing potential censorship or an orchestrated rollback of the network.
Solana Labs co-founder, Anatoly Yakovenko, tried to downplay the situation by comparing this emergency to the coordination capability of key Ethereum players in case of critical bugs. But this analogy was strongly contested by a prominent Ethereum community member, Ryan Berckmans.
According to Berckmans, the fundamental difference lies in the diversity of clients. While Geth represents a maximum of 41% of the Ethereum market, Solana currently has only one fully operational client: Agave.
People are missing the important points in this Solana emergency fork situation
1) Eth has client diversity and a protocol spec steered by a meaningful research community.
The most popular eth client, geth, has at most 41% market share.
Sol has one prod client (just one; don't integrate yet!) and no real protocol spec research community.
2) This isn't an anomaly. It's a critical bug in a core crypto primitive used across many chains.
According to Berckmans, the integrality of Agave makes any bug a direct vulnerability of the Solana protocol, rendering the separation between application and protocol nearly meaningless.
“On Solana, a bug in the sole available client is, de facto, a protocol bug. Modifying the client is equivalent to modifying the protocol. There is no functional separation,” he lamented.
However, Solana Foundation is banking on the arrival of the alternative client Firedancer in 2025, aimed at enhancing network resilience and robustness. But according to Berckmans, Solana would need at least three distinct clients to claim true protocol-level decentralization.
The Solana security flaw highlights the unique challenges of centralized-governance blockchains, a major concern for French and European stakeholders – regulators, investors, or developers.
As Europe refines the MiCA regulatory framework, the robustness of the underlying infrastructure of issued tokens becomes critically important. This incident could thus serve as a lesson for future certifications or criteria for integrating digital asset projects.
While Solana demonstrated exemplary responsiveness, the method employed raises legitimate concerns about the network’s technical governance. Client diversity, transparency in incident management, and the ability to weather crises without compromising neutrality are now crucial analytical criteria.
If you can call up the validator nodes to coordinate a critical zero day bug fix, you can call them up to do whatever you want. This is NOT the decentralisation we should be striving for.
And CT is celebrating this as "security is important" #Solana 🙄
The Solana security flaw is a wake-up call: the pursuit of performance and innovation cannot come at the expense of fundamental decentralization principles. An important reminder for the entire crypto ecosystem, at a time when issues of trust and security are more crucial than ever.
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 以太坊,交易量和SEC的积分:导航监管景观
- 2025-08-06 22:05:31
- 以太坊的交易量在SEC Staking指导中涌现,提出了乐观和监管问题。这对Defi和Crypto的未来意味着什么?
-
- 加密市场的嗡嗡声:证明是共同案例,二元列表令牌
- 2025-08-06 22:00:30
- 加密市场将新的动态视为简洁的象征性收益在Coinbase和Binance等主要交易所的列表之后。是什么推动了这一激增?
-
- 巴西,比特币,听证日期:巴西要拥抱比特币吗?
- 2025-08-06 20:00:10
- 巴西代表会议将于2025年8月20日举行公开听证会,讨论在其国家储备中增加比特币。这可以改变游戏规则吗?
-
-
- Wewake Finance:这是您一直在等待的加密ROI机会吗?
- 2025-08-06 20:00:00
- 探索Wewake Finance对Web3可访问性的创新方法及其在不断发展的加密景观中的高ROI潜力。
-
- Pancakeswap,美国股票和永久合同:Defi的新边界
- 2025-08-06 19:53:39
- Pancakeswap潜入美国的股票代币永久合同,与传统的金融架起融合。这是分散交易的未来吗?
-
-
- 加密,东盟和菲律宾:Web3的后起之秀?
- 2025-08-06 19:51:28
- 菲律宾将自己定位为东盟的Web3中心。即将举行的事件和像特朗普这样的主要参与者会加速加密货币的采用?
-