Solana Fixes Zero-Day Vulnerability in Token-22 Confidential Tokens

Solana Patches Critical Zero-Day Vulnerability in Token-22 System, Sparks Centralization Debate

  • Solana Foundation has patched a zero-day vulnerability affecting Token-22 confidential tokens that could have allowed attackers to mint and steal tokens.
  • Validators quickly implemented patches for the security bug discovered on April 16, with no reported exploits occurring.
  • The private handling of the patch has sparked centralization debates between Solana and Ethereum community members.

The Solana Foundation has successfully fixed a zero-day vulnerability that could have allowed attackers to forge proofs, potentially enabling them to mint and withdraw certain tokens from user accounts. According to a May 3 post-mortem released by the Foundation, the security flaw, initially discovered on April 16, targeted Solana’s privacy-focused Token-22 confidential tokens.

- Advertisement -

No exploits of the vulnerability have been reported, and Solana validators have implemented the patched version, as confirmed by the Foundation. The vulnerability specifically affected two programs: Token-2022, which handles main application logic for token mints and accounts, and ZK ElGamal Proof, which verifies zero-knowledge proofs for account balances.

The security issue stemmed from certain algebraic components being omitted from the hash in the Fiat-Shamir Transformation’s transcript generation. This flaw could have allowed attackers to exploit these unhashed components by creating forged proofs to mint and steal Token-22 confidential tokens, which leverage zero-knowledge proofs for private transfers.

Swift Response from Solana Ecosystem

After identification on April 16, two patches were deployed to fix the issues, with a super majority of Solana validators implementing them approximately two days later. Development firms Anza, Firedancer, and Jito led the security patch effort, with assistance from Asymmetric Research, Neodyme, and OtterSec. The Foundation has assured users that all funds remain secure.

However, the private handling of the vulnerability has raised centralization concerns within the crypto community. A Curve Finance contributor questioned the Foundation’s close relationship with validators, asking, "Why does someone have a list of all validators and their contact details? What else are they talking about in those comms channels."

Solana Labs CEO Anatoly Yakovenko responded by suggesting that Ethereum community members could similarly coordinate to fix security issues, noting that more than 70% of Ethereum network validators are controlled by exchanges or staking operators.

- Advertisement -

Centralization Debate Intensifies

Ethereum community member Ryan Berckmans countered Yakovenko’s comparison, highlighting that Ethereum has better client diversity with its most popular client having at most 41% market share. In contrast, Solana currently has just one production-ready client, Agave.

"This means zero day bugs in the single Sol client are de facto protocol bugs. Change the single client program, change the protocol itself. The client is the protocol," Berckmans wrote.

- Advertisement -

Solana plans to launch a new client, Firedancer, in the coming months to improve network resilience. However, Berckmans argues that Solana would need at least three clients to achieve sufficient decentralization at the client level.

This isn’t the first time Solana has privately resolved a critical vulnerability. In August, the Foundation and network validators fixed another security flaw behind the scenes, with executive director Dan Albert stating that coordination ability doesn’t equate to centralization.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Shopify, Coinbase Launch USDC Payments; Mastercard Expands Crypto Access

Shopify and Coinbase allow merchants to accept USDC stablecoin payments, making crypto transactions easier...

Coinbase Launches Wrapped ADA and LTC on Base, COIN Hits New High

Coinbase has introduced wrapped versions of Cardano (ADA) and Litecoin (LTC) on its Ethereum...

ClickFix Attacks Surge 517% in 2025, Fake CAPTCHAs Spread Malware

ClickFix attacks using fake CAPTCHA verifications have risen by 517% in early 2025, according...

FHFA Orders Fannie, Freddie to Consider Crypto as Mortgage Collateral

The U.S. Federal Housing Finance Agency ordered Fannie Mae and Freddie Mac to consider...

Retail Investors Can Now Buy Tokenized Shares of SpaceX via Blockchain

Retail investors can now buy blockchain-based fractional shares in SpaceX through Republic. These digital tokens...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...