BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Solana Fixes Zero-Day Vulnerability in Token-22 Confidential Tokens

Solana Patches Critical Zero-Day Vulnerability in Token-22 System, Sparks Centralization Debate

  • Solana Foundation has patched a zero-day vulnerability affecting Token-22 confidential tokens that could have allowed attackers to mint and steal tokens.
  • Validators quickly implemented patches for the security bug discovered on April 16, with no reported exploits occurring.
  • The private handling of the patch has sparked centralization debates between Solana and Ethereum community members.

The Solana Foundation has successfully fixed a zero-day vulnerability that could have allowed attackers to forge proofs, potentially enabling them to mint and withdraw certain tokens from user accounts. According to a May 3 post-mortem released by the Foundation, the security flaw, initially discovered on April 16, targeted Solana’s privacy-focused Token-22 confidential tokens.

- Advertisement -

No exploits of the vulnerability have been reported, and Solana validators have implemented the patched version, as confirmed by the Foundation. The vulnerability specifically affected two programs: Token-2022, which handles main application logic for token mints and accounts, and ZK ElGamal Proof, which verifies zero-knowledge proofs for account balances.

The security issue stemmed from certain algebraic components being omitted from the hash in the Fiat-Shamir Transformation’s transcript generation. This flaw could have allowed attackers to exploit these unhashed components by creating forged proofs to mint and steal Token-22 confidential tokens, which leverage zero-knowledge proofs for private transfers.

Swift Response from Solana Ecosystem

After identification on April 16, two patches were deployed to fix the issues, with a super majority of Solana validators implementing them approximately two days later. Development firms Anza, Firedancer, and Jito led the security patch effort, with assistance from Asymmetric Research, Neodyme, and OtterSec. The Foundation has assured users that all funds remain secure.

However, the private handling of the vulnerability has raised centralization concerns within the crypto community. A Curve Finance contributor questioned the Foundation’s close relationship with validators, asking, "Why does someone have a list of all validators and their contact details? What else are they talking about in those comms channels."

- Advertisement -

Solana Labs CEO Anatoly Yakovenko responded by suggesting that Ethereum community members could similarly coordinate to fix security issues, noting that more than 70% of Ethereum network validators are controlled by exchanges or staking operators.

Centralization Debate Intensifies

Ethereum community member Ryan Berckmans countered Yakovenko’s comparison, highlighting that Ethereum has better client diversity with its most popular client having at most 41% market share. In contrast, Solana currently has just one production-ready client, Agave.

"This means zero day bugs in the single Sol client are de facto protocol bugs. Change the single client program, change the protocol itself. The client is the protocol," Berckmans wrote.

Solana plans to launch a new client, Firedancer, in the coming months to improve network resilience. However, Berckmans argues that Solana would need at least three clients to achieve sufficient decentralization at the client level.

This isn’t the first time Solana has privately resolved a critical vulnerability. In August, the Foundation and network validators fixed another security flaw behind the scenes, with executive director Dan Albert stating that coordination ability doesn’t equate to centralization.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Goldman Sachs Rates China’s Pony.ai, WeRide Robotaxi Stocks

Goldman Sachs initiated Buy ratings on Chinese Robotaxi leaders Pony.ai (PONY) and WeRide (WRD),...

Crypto Scammer Gets 23 Years for $20M Fraud

Robert Dunlap was sentenced to 23 years in prison for a cryptocurrency fraud scheme...

Active ApacheMQ Bug CVE-2026-34197 Exploited in Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns a high-severity flaw in Apache...

Netflix Stock Plummets 9% on Weak Forecast, Founder’s Exit

Netflix stock plunged nearly 9% in after-hours trading following its Q1 2026 earnings report,...

Tether backs Drift’s $150M hack recovery, eyes Solana

Tether is supporting a recovery plan for the hacked Solana exchange Drift Protocol, which...

Must Read

Sushiswap vs Uniswap, What are the differences between these dex?

It's no secret that the world of decentralized exchanges has exploded in recent years. Many of you are probably wondering what the difference is...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading