Solana Fixes Major Bug That Could Let Hackers Create Fake Tokens or Withdraw Funds

SOL Solana
The flaw was disclosed on April 16 via a GitHub advisory posted by Anza, a Solana development team, along with a working proof-of-concept.
Crypto Journalist
Crypto Journalist
Amin Ayan
About Author

Amin Ayan is a crypto journalist with over four years of experience in the industry. He has contributed to leading publications such as Cryptonews, Investing.com, 99Bitcoins, and 24/7 Wall St. He has...

Last updated: 
Why Trust Cryptonews
Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas - from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

The Solana Foundation has addressed a critical bug in its privacy-focused token system that, if exploited, could have allowed malicious actors to forge zero-knowledge proofs and perform unauthorized token minting or withdrawals.

The flaw was disclosed on April 16 via a GitHub advisory posted by Anza, a Solana development team, along with a working proof-of-concept.

Engineers from Anza, Firedancer, and Jito promptly confirmed the issue and began remediation efforts, according to a post-mortem published Saturday.

Solana Bug Traced to ZK ElGamal Proof System

At the core of the vulnerability was the ZK ElGamal Proof program, which validates zero-knowledge proofs (ZKPs) used in Solana’s Token-22 confidential transfers.

These token extensions are designed to enable privacy-preserving transactions by encrypting token balances and using cryptographic proofs to validate transfers.

Zero-knowledge proofs allow users to prove the validity of a transaction without revealing sensitive information, such as the amount or recipient address.

However, in this instance, a key algebraic component was missing from the hashing process used in the Fiat-Shamir transformation—a common technique that converts interactive proofs into non-interactive ones suitable for blockchain verification.

The oversight created a potential backdoor where sophisticated attackers could craft fake proofs that would be mistakenly accepted by the on-chain verifier.

Such an exploit could have enabled unauthorized minting of tokens or withdrawals from wallets without permission.

Fortunately, the vulnerability did not affect standard SPL tokens or the main Token-2022 logic.

Private patches were quickly distributed to validator operators on April 17, with a second patch released later that day to address a related issue.

External security firms Asymmetric Research, Neodyme, and OtterSec reviewed the fixes.

By April 18, the majority of validators had implemented the patch.

According to Solana’s post-mortem, there is no evidence the flaw was ever exploited, and all user funds remain safe.

Solana Leads Blockchain Revenue Race in Q1 2025

Solana has taken the lead among blockchain networks in Q1 2025, outpacing competitors like Ethereum and BNB Chain in total revenue.

This marks a major milestone for the high-speed blockchain, driven by a surge in user engagement and an expanding ecosystem.

The network’s revenue boost was powered by increased decentralized app (dApp) usage, NFT transactions, and overall on-chain activity.

Solana’s scalable architecture and low fees continue to attract developers and users alike, making it a preferred platform for high-volume applications.

Its growth was further supported by upgrades, strategic partnerships, and momentum in sectors like DeFi, gaming, and mobile crypto apps.

These developments have solidified Solana’s reputation as a user-friendly, high-performance blockchain with a strong outlook for the rest of 2025.

Logo

Why Trust Cryptonews

In the Article
Solana
SOL
$168.06
2.04 %
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors
editors
+ 66 More

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,395,373,143,555
-2.76
Trending Crypto

More Articles

Price Analysis
XRP Price Prediction: XRP Builds Momentum at $2.38 as Key Resistance Levels Come Into Focus for Traders
Arslan Butt
Arslan Butt
2025-05-17 14:58:01
Altcoin News
Sequoia Partner Caught in Coinbase Data Breach, More VCs May Be Affected
Amin Ayan
Amin Ayan
2025-05-17 14:10:00
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors