• Latest
  • All
  • Breaking
  • Announcements
  • Learn
  • Analysis
  • Current events
Solana Quietly Fixes Bug That Could Have Let Attackers Mint and Steal Certain Tokens

Solana Quietly Fixes Bug That Could Have Let Attackers Mint and Steal Certain Tokens

May 5, 2025

Here’s what happened in crypto today

December 5, 2025
Solana and Coinbase’s Base connect together using Chainlink

Solana and Coinbase’s Base connect together using Chainlink

December 5, 2025
Ex-Signature Bank execs launch blockchain-powered bank N3XT

Ex-Signature Bank execs launch blockchain-powered bank N3XT

December 5, 2025
XRP sentiment plummets, which could set token up for rally: Santiment

XRP sentiment plummets, which could set token up for rally: Santiment

December 5, 2025
Bitcoin unlikely to replicate January’s surge to new high: 21Shares founder

Bitcoin unlikely to replicate January’s surge to new high: 21Shares founder

December 5, 2025
US investors consider crypto less as risk-taking drops: FINRA study

US investors consider crypto less as risk-taking drops: FINRA study

December 5, 2025
Ethereum sees 25% validation drop post-Fusaka as Prysm bug nears finality loss

Ethereum sees 25% validation drop post-Fusaka as Prysm bug nears finality loss

December 5, 2025
Bitcoin price action, investor sentiment point to bullish December

Bitcoin price action, investor sentiment point to bullish December

December 5, 2025
In wake of crypto’s leverage wipeout, SEC approves ‘SUI-on-steroids’ ETF

In wake of crypto’s leverage wipeout, SEC approves ‘SUI-on-steroids’ ETF

December 5, 2025
CNBC taps Kalshi to bring real-time prediction data into financial coverage

CNBC taps Kalshi to bring real-time prediction data into financial coverage

December 5, 2025
Former Binance.US CEO launches stablecoin platform ahead of L1 network

Former Binance.US CEO launches stablecoin platform ahead of L1 network

December 5, 2025
Hua Xia state-linked Chinese bank tokenizes $600M in yuan bonds

Hua Xia state-linked Chinese bank tokenizes $600M in yuan bonds

December 5, 2025
Friday, December 5, 2025
8V Crypto Academy
8V Academy - 8V.com - Your Cryptocurrency Gateway
  • About 8V
    • 8V Exchange
    • 8V Blog
  • Market Beat
    • Today Real-time Market Data
    • Web3
    • Breaking
    • Tokens
    • Markets
    • Compliance
    • Exchanges
    • Tech
    • GameFi
    • NFT
    • Defi
    • Miscellaneous
  • Platform
    • 8V Announcements
    • Events
      • Current Events
      • Closed Events
    • Product
      • 8V Overview
      • Assets
      • Exchange
        • Spot Trading
        • Futures Trading
        • Leverage Trading
      • Copy Trading
      • Earn
        • Fixed
        • Flexible
      • Cryptocurrency Debit Card
      • Buy Crypto Instantly
      • Strategy Trading
    • Trading Fees and Limits
    • 8V Exchange API
    • Referral Scheme
    • Bug Bounty
    • FAQ
      • 8V Cryptocurrency Card
      • Account Functions
      • Deposits & Withdrawals
      • Contract Related
      • 8V LaunchX Protocol
      • Others
  • Academy
    • How To Buy Crypto
    • Learning Center
    • Analysis Center
    • Crypto Glossary
  • Business
    • Coin Listing Request
    • Crypto Trader Application
    • Partnerships
  • Policy
    • Privacy Policy
    • Service Agreement
    • Disclaimer
    • Compliance Notice
  • English
    • English
    • 中文 (台灣)
    • 中文 (中国)
  • Login
  • Register
No Result
View All Result
  • About 8V
    • 8V Exchange
    • 8V Blog
  • Market Beat
    • Today Real-time Market Data
    • Web3
    • Breaking
    • Tokens
    • Markets
    • Compliance
    • Exchanges
    • Tech
    • GameFi
    • NFT
    • Defi
    • Miscellaneous
  • Platform
    • 8V Announcements
    • Events
      • Current Events
      • Closed Events
    • Product
      • 8V Overview
      • Assets
      • Exchange
        • Spot Trading
        • Futures Trading
        • Leverage Trading
      • Copy Trading
      • Earn
        • Fixed
        • Flexible
      • Cryptocurrency Debit Card
      • Buy Crypto Instantly
      • Strategy Trading
    • Trading Fees and Limits
    • 8V Exchange API
    • Referral Scheme
    • Bug Bounty
    • FAQ
      • 8V Cryptocurrency Card
      • Account Functions
      • Deposits & Withdrawals
      • Contract Related
      • 8V LaunchX Protocol
      • Others
  • Academy
    • How To Buy Crypto
    • Learning Center
    • Analysis Center
    • Crypto Glossary
  • Business
    • Coin Listing Request
    • Crypto Trader Application
    • Partnerships
  • Policy
    • Privacy Policy
    • Service Agreement
    • Disclaimer
    • Compliance Notice
  • English
    • English
    • 中文 (台灣)
    • 中文 (中国)
  • Login
  • Register
No Result
View All Result
8V Crypto Academy
No Result
View All Result

8V Crypto Academy » Solana Quietly Fixes Bug That Could Have Let Attackers Mint and Steal Certain Tokens

Solana Quietly Fixes Bug That Could Have Let Attackers Mint and Steal Certain Tokens

May 5, 2025
in Breaking, News
Reading Time: 8 mins read
A A

BTC

$94,876.89

–

0.85%

ETH

$1,828.13

–

0.17%

USDT

$1.0019

+

0.08%

XRP

RelatedPosts

Here’s what happened in crypto today

Solana and Coinbase’s Base connect together using Chainlink

Ex-Signature Bank execs launch blockchain-powered bank N3XT

XRP sentiment plummets, which could set token up for rally: Santiment

$2.1879

–

0.48%

BNB

$592.97

–

0.50%

SOL

$147.04

+

1.15%

USDC

$1.0016

+

0.08%

DOGE

$0.1739

–

0.26%

ADA

$0.6888

–

0.49%

TRX

$0.2487

+

0.37%

SUI

$3.4258

+

6.26%

LINK

$14.13

+

0.66%

LEO

$9.1021

+

1.10%

AVAX

$20.05

–

0.43%

XLM

$0.2688

+

0.19%

SHIB

$0.0₄1300

–

0.15%

TON

$3.0373

–

1.96%

HBAR

$0.1780

–

0.19%

BCH

$361.10

+

0.81%

HYPE

$20.70

+

0.87%

Markets

Share this article

By Shaurya Malwa|Edited by Parikshit Mishra

May 5, 2025, 7:10 a.m.

Bug (CoinDesk Archives)
  • The Solana Foundation revealed a vulnerability in its token system that could have allowed unauthorized minting or withdrawals.
  • The flaw was related to the ZK ElGamal Proof program, affecting confidential transfers but not standard SPL tokens.

The Solana Foundation has disclosed a previously unknown vulnerability in its privacy-focused token system that could have allowed attackers to forge fake zero-knowledge proofs, enabling unauthorized minting or withdrawals of tokens.

The vulnerability was first reported on April 16 through Anza’s GitHub security advisory, accompanied by a working proof-of-concept. Engineers from Solana development teams Anza, Firedancer, and Jito verified the bug and began working on a fix immediately, per a post-mortem published Saturday,

STORY CONTINUES BELOW

Don’t miss another story.Subscribe to the Crypto Long & Short Newsletter today.See all newslettersBy signing up, you will receive emails about CoinDesk products and you agree to ourterms of useandprivacy policy.

The issue stemmed from the ZK ElGamal Proof program, which verifies zero-knowledge proofs (ZKPs) used in Solana’s Token-22 confidential transfers. These extension tokens enable private balances and transfers by encrypting amounts and using cryptographic proofs to validate them.

ZKPs are a cryptographic method that lets someone prove they know or have access to something, such as a password or age, without revealing the thing itself.

In crypto applications, these can be used to prove a transaction is valid without showing specific amounts or addresses (which can otherwise be used by malicious actors to plan exploits).

The bug occurred because some algebraic components were missing from the hashing process during the Fiat-Shamir transformation — a standard method to make zero-knowledge proofs non-interactive. (Non-interactive means turning a back-and-forth process into a one-time proof anyone can verify.)

A sophisticated attacker could forge invalid proofs that the on-chain verifier would still accept.

This would have allowed unauthorized actions such as minting unlimited tokens or withdrawing tokens from other accounts.

As such, the vulnerability did not affect standard SPL tokens or the main Token-2022 program logic.

Patches were distributed privately to validator operators beginning April 17. A second patch was pushed later that evening to address a related issue elsewhere in the codebase.

Both were reviewed by third-party security firms Asymmetric Research, Neodyme, and OtterSec. By April 18, a supermajority of validators had adopted the fix.

There is no indication that the bug was exploited, and all funds remain secure, according to the post-mortem.

Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.

Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME, BURGER, SPIRIT, and ORCA.

He provides over $1,000 to liquidity pools on Compound, Curve, SushiSwap, PancakeSwap, BurgerSwap, Orca, AnySwap, SpiritSwap, Rook Protocol, Yearn Finance, Synthetix, Harvest, Redacted Cartel, OlympusDAO, Rome, Trader Joe, and SUN.

Shaurya Malwa

 

Previous Post

Donald Trump Denies Claims of Profiting From TRUMP Token

Next Post

Ether-Bitcoin ‘Squeeze’ Hints at Imminent Volatility as Ethereum Pectra Upgrade Nears

Related Posts

Breaking

Here’s what happened in crypto today

December 5, 2025
Solana and Coinbase’s Base connect together using Chainlink
Breaking

Solana and Coinbase’s Base connect together using Chainlink

December 5, 2025
Ex-Signature Bank execs launch blockchain-powered bank N3XT
Breaking

Ex-Signature Bank execs launch blockchain-powered bank N3XT

December 5, 2025
XRP sentiment plummets, which could set token up for rally: Santiment
Breaking

XRP sentiment plummets, which could set token up for rally: Santiment

December 5, 2025
Bitcoin unlikely to replicate January’s surge to new high: 21Shares founder
Breaking

Bitcoin unlikely to replicate January’s surge to new high: 21Shares founder

December 5, 2025
US investors consider crypto less as risk-taking drops: FINRA study
Breaking

US investors consider crypto less as risk-taking drops: FINRA study

December 5, 2025
Next Post
Ether-Bitcoin ‘Squeeze’ Hints at Imminent Volatility as Ethereum Pectra Upgrade Nears

Ether-Bitcoin 'Squeeze' Hints at Imminent Volatility as Ethereum Pectra Upgrade Nears

No Result
View All Result
深入分析 穩定幣脫鉤 DeFi USDX事件
Analysis

In-depth analysis of the stablecoin depeg from DeFi and the USDX event

by 8V
November 10, 2025
0

Last week's stablecoin depegging once again shook the decentralized finance (DeFi) world, with USDX, a synthetic stablecoin issued by Stable...

Read moreDetails
$60 Million Mistake, $19 Billion Nightmare: How Oracle Broke the Crypto Market

$60 Million Mistake, $19 Billion Nightmare: How Oracle Broke the Crypto Market

October 21, 2025
8V深度分析Aave V3借贷机制、流动性和风险管理

8V in-depth analysis – the Aave V3 lending e-mode mechanism

September 30, 2025
Polymarket和8V交易所對加密貨幣產業的意義

The Significance of Polymarket and 8V Exchange

September 16, 2025
Q4 Crypto Investment Strategy - 8V Crypto Academy

Q4 Crypto Investment Strategy

August 19, 2025
8v.com - download APP 8v.com - download APP 8v.com - download APP
  • About 8V
  • Download APP
  • Announcements
  • Breaking News
  • RSS Feeds
  • FAQ
  • Service Agreement
  • Privacy Policy
  • Disclaimer

© 2025 8V.com - 8V Crypto Academy - Empower your crypto journey! 8V.com

No Result
View All Result
  • About 8V
    • 8V Exchange
    • 8V Blog
  • Market Beat
    • Today Real-time Market Data
    • Web3
    • Breaking
    • Tokens
    • Markets
    • Compliance
    • Exchanges
    • Tech
    • GameFi
    • NFT
    • Defi
    • Miscellaneous
  • Platform
    • 8V Announcements
    • Events
      • Current Events
      • Closed Events
    • Product
      • 8V Overview
      • Assets
      • Exchange
      • Copy Trading
      • Earn
      • Cryptocurrency Debit Card
      • Buy Crypto Instantly
      • Strategy Trading
    • Trading Fees and Limits
    • 8V Exchange API
    • Referral Scheme
    • Bug Bounty
    • FAQ
      • 8V Cryptocurrency Card
      • Account Functions
      • Deposits & Withdrawals
      • Contract Related
      • 8V LaunchX Protocol
      • Others
  • Academy
    • How To Buy Crypto
    • Learning Center
    • Analysis Center
    • Crypto Glossary
  • Business
    • Coin Listing Request
    • Crypto Trader Application
    • Partnerships
  • Policy
    • Privacy Policy
    • Service Agreement
    • Disclaimer
    • Compliance Notice
  • English
    • English
    • 中文 (台灣)
    • 中文 (中国)
  • Login
  • Register

© 2025 8V.com - 8V Crypto Academy - Empower your crypto journey! 8V.com