Solana Fixes Confidential Token Vulnerability, Sparks Centralization Debate
- Solana Foundation fixes bug affecting Token-2022 and ZK ElGamal Proof that could have permitted unauthorized minting.
- Due to this bug, the attackers could have targeted the unhashed components by creating a fake identity that easily passes verification.
The Solana Foundation has recently encountered a bug that allowed hackers to mint some tokens and even take those tokens from users’ accounts. However, the bug has been reportedly fixed now.
The Foundation’s analysis reveals that the vulnerability was first found on April 16, and it could have permitted a hacker to proceed with an invalid proof affecting the privacy of the blockchain platform, permitting Token-22 confidential tokens.
Also, it mentioned that no known exploit of the vulnerability has been reported, and since then, the validators of Solana have adopted the patched version. The bug primarily bothered two programs, Token-2022 and ZK ElGamal Proof.
Token-2022 is responsible for managing the main app logic for token mints and accounts. On the other hand, ZK ElGamal Proof verified the accuracy of zero-knowledge proofs to show precise account balances.
As per the foundation, some algebraic components were removed from the hash in the Fiat-Shamir Transformation’s transcript generation, which identifies the creation of public randomness using a cryptographic hash function.
Due to this bug, the attackers could have targeted the unhashed components by creating a fake identity that easily passes verification to mint and steal Token-22 confidential tokens. To resolve this major issue, two patches were placed.
The Centralization Scrutiny
A lot of Solana validators, including Anza, Firedancer, and Jit,o adopted the patches after two days of encountering the issue. Other firms such as Asymmetric Research, Neodyme, and OtterSec also facilitated it.
The Foundation also noted that no funds have been tampered with and it is safe till now. Regardless of this, the validators have raised centralization concerns within the crypto community. One of them was a Curve Finance contributor who was concerned about the close relationship of the Foundation with Solana validators.
It mentioned that the main issue is that everything was done privately, and now the bad actors already know that these channels exist, and it is a centralized point of failure in a decentralized system.
Highlighted Crypto News Today:
Arizona Governor Blocks Bill to Hold Bitcoin in State Reserves
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Last Shot to Flip $2K into $72K with Troller Cat – The Best New Meme Coin to Invest in Now as Shiba Inu and Dogwifhat Fight Bears
Shiba Inu trends, Dogwifhat gains traction, but Troller Cat's live presale is turning heads—positioning it among the Best New Meme Coins to Invest in Now.Last Hours of Stage 6: Join Presale Before Troller Cat’s Valuation SurgesDogwifhat Slides 5% to $0.00305 as Trading Volume and Momentum Cool OffShiba Inu Dips 7.35% to $0.00001336 as Market Cap Shrinks but Volume Jumps 43%Conclusion: Only One Presale is Offering Life-Changing ROI Potential Right Now

2025’s Top Cryptos to Invest in Right Now: Qubetics’ Secure Ecosystem, Tron’s Lending Leap, and Stellar’s Cross-Border AI Push
Explore why Qubetics, Tron, and Stellar are making headlines in 2025. Learn what makes them the top cryptos to invest in right now.Qubetics ($TICS) — Solving Real-World Blockchain Gaps with PrecisionTron (TRX) — Cementing Its Role in the Stablecoin EconomyStellar (XLM) — Revamping Cross-Border Payments with AI AssistanceConclusion

Capturing Whale Attention: 69% APY Makes Troller Cat One of the Best 100x Cryptos as Brett Slows and Keyboard Cat Stir
Discover the best 100x crypto opportunities as Troller Cat surges in presale, while Brett stumbles and Keyboard Cat gains momentum.Troller Cat ($TCAT): The Best 100x Crypto Presale Opportunity Right NowBrett ($BRETT): A Strong Start, but Signs of SlowdownKeyboard Cat ($KEYCAT): The Nostalgia Play Gaining Quiet MomentumConclusion

Pi Network Launches FruityPi and Targets Engagement with Real-World Cryptocurrency Usage
Trending news
MoreCrypto prices
More








