{"id":14460,"date":"2025-05-05T11:50:06","date_gmt":"2025-05-05T11:50:06","guid":{"rendered":"https:\/\/www.cryptometer.io\/news\/?p=14460"},"modified":"2025-05-05T11:50:09","modified_gmt":"2025-05-05T11:50:09","slug":"solana-devs-resolve-confidential-token-exploit-risk","status":"publish","type":"post","link":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/","title":{"rendered":"Solana Devs Resolve Confidential Token Exploit Risk"},"content":{"rendered":"\n<p>Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential tokens or even withdraw them from user accounts. While no exploitation was reported, the coordinated and discreet nature of the fix has reignited criticism over Solana\u2019s decentralization.<\/p>\n\n\n\n<p>The Solana Foundation confirmed in a May 3 post-mortem that the issue, first discovered on April 16, has been resolved. The bug was related to Token-2022 and ZK ElGamal Proof\u2014two components integral to Solana\u2019s privacy-focused token system.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-the-bug-worked\">How the Bug Worked<\/h3>\n\n\n\n<p>The vulnerability stemmed from the Fiat-Shamir Transformation process used in generating zero-knowledge proofs. Specifically, certain algebraic elements were left out of the cryptographic hash, which opened the door for attackers to forge a valid-looking proof. This flaw could have enabled the creation and theft of confidential tokens designed for private transfers.<\/p>\n\n\n\n<p>These tokens, part of Solana\u2019s Token-22 \u201cExtension Tokens,\u201d rely on zero-knowledge cryptography to enhance privacy and functionality in token transfers.<\/p>\n\n\n\n<p>Solana acted quickly, deploying two patches within days. A supermajority of validators implemented the fix shortly thereafter. Development firms Anza, Firedancer, and Jito led the patch rollout, with support from security researchers at Asymmetric Research, Neodyme, and OtterSec.<\/p>\n\n\n\n<p>The Solana Foundation reassured the community that no user funds were compromised.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-centralization-debate-rekindled\">Centralization Debate Rekindled<\/h3>\n\n\n\n<p>Despite the fast response, the way the Solana Foundation privately coordinated the patch with validators has raised new questions about network decentralization. A contributor to Curve Finance expressed concern over the foundation\u2019s apparent access to direct contact information for all validators, fearing potential for collusion or censorship.<\/p>\n\n\n\n<p>Solana Labs CEO Anatoly Yakovenko pushed back, noting that Ethereum validators\u2014many operated by large entities like Lido, Coinbase, and Binance\u2014could also be mobilized to implement a security patch if needed.<\/p>\n\n\n\n<p>Yakovenko argued that coordinated bug fixes are not exclusive to Solana. \u201cIf geth needs to push a patch, I\u2019ll be happy to coordinate for them,\u201d he said.<\/p>\n\n\n\n<p>This isn\u2019t the first time Solana\u2019s behind-the-scenes handling of security flaws has drawn criticism. A similar incident occurred in August when another major bug was patched without public disclosure until after resolution. At the time, the foundation defended its process, saying that effective coordination doesn\u2019t equate to centralization.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential tokens or even withdraw them from user accounts. While no exploitation was reported, the coordinated and discreet nature of the fix has reignited criticism over Solana\u2019s decentralization. The Solana Foundation confirmed in a May 3 [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":3635,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[259,2,43],"tags":[],"class_list":{"0":"post-14460","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-altcoins","8":"category-featured","9":"category-general-news"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Solana Devs Resolve Confidential Token Exploit Risk<\/title>\n<meta name=\"description\" content=\"Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Solana Devs Resolve Confidential Token Exploit Risk\" \/>\n<meta property=\"og:description\" content=\"Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"CryptoMeter.io\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-05T11:50:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-05T11:50:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"499\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Manjeet Mane\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@CryptoMeterIO\" \/>\n<meta name=\"twitter:site\" content=\"@CryptoMeterIO\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Manjeet Mane\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/\"},\"author\":{\"name\":\"Manjeet Mane\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/#\/schema\/person\/294f2836271d1655ea8e2e5619466eb8\"},\"headline\":\"Solana Devs Resolve Confidential Token Exploit Risk\",\"datePublished\":\"2025-05-05T11:50:06+00:00\",\"dateModified\":\"2025-05-05T11:50:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/\"},\"wordCount\":380,\"publisher\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg\",\"articleSection\":[\"Altcoins\",\"Featured\",\"General News\"],\"inLanguage\":\"en-US\",\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/\",\"url\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/\",\"name\":\"Solana Devs Resolve Confidential Token Exploit Risk\",\"isPartOf\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg\",\"datePublished\":\"2025-05-05T11:50:06+00:00\",\"dateModified\":\"2025-05-05T11:50:09+00:00\",\"description\":\"Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage\",\"url\":\"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg\",\"contentUrl\":\"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg\",\"width\":800,\"height\":499,\"caption\":\"solana\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cryptometer.io\/news\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Solana Devs Resolve Confidential Token Exploit Risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/#website\",\"url\":\"https:\/\/www.cryptometer.io\/news\/\",\"name\":\"CryptoMeter.io\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/#organization\"},\"alternateName\":\"CryptoMeter.io\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cryptometer.io\/news\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/#organization\",\"name\":\"CryptoMeter.io\",\"url\":\"https:\/\/www.cryptometer.io\/news\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/i0.wp.com\/www.cryptometer.io\/news\/wp-content\/uploads\/2023\/01\/cropped-favicon_large.png?fit=512%2C512&ssl=1\",\"contentUrl\":\"https:\/\/i0.wp.com\/www.cryptometer.io\/news\/wp-content\/uploads\/2023\/01\/cropped-favicon_large.png?fit=512%2C512&ssl=1\",\"width\":512,\"height\":512,\"caption\":\"CryptoMeter.io\"},\"image\":{\"@id\":\"https:\/\/www.cryptometer.io\/news\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/CryptoMeterIO\"],\"publishingPrinciples\":\"https:\/\/www.cryptometer.io\/news\/about-us\/\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cryptometer.io\/news\/#\/schema\/person\/294f2836271d1655ea8e2e5619466eb8\",\"name\":\"Manjeet Mane\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/496227b2ca2c6045749260e74082028192b686959152b44fa23f9c0751c7781a?s=96&d=retro&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/496227b2ca2c6045749260e74082028192b686959152b44fa23f9c0751c7781a?s=96&d=retro&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/496227b2ca2c6045749260e74082028192b686959152b44fa23f9c0751c7781a?s=96&d=retro&r=g\",\"caption\":\"Manjeet Mane\"},\"description\":\"Manjeet Mane, an accomplished developer in cryptocurrency and blockchain technology, has devoted years to advancing these fields. With a firm belief in their transformative power across industries, he specializes in full-stack development.\",\"url\":\"https:\/\/www.cryptometer.io\/news\/author\/manjit\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Solana Devs Resolve Confidential Token Exploit Risk","description":"Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/","og_locale":"en_US","og_type":"article","og_title":"Solana Devs Resolve Confidential Token Exploit Risk","og_description":"Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential","og_url":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/","og_site_name":"CryptoMeter.io","article_published_time":"2025-05-05T11:50:06+00:00","article_modified_time":"2025-05-05T11:50:09+00:00","og_image":[{"width":800,"height":499,"url":"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg","type":"image\/jpeg"}],"author":"Manjeet Mane","twitter_card":"summary_large_image","twitter_creator":"@CryptoMeterIO","twitter_site":"@CryptoMeterIO","twitter_misc":{"Written by":"Manjeet Mane","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#article","isPartOf":{"@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/"},"author":{"name":"Manjeet Mane","@id":"https:\/\/www.cryptometer.io\/news\/#\/schema\/person\/294f2836271d1655ea8e2e5619466eb8"},"headline":"Solana Devs Resolve Confidential Token Exploit Risk","datePublished":"2025-05-05T11:50:06+00:00","dateModified":"2025-05-05T11:50:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/"},"wordCount":380,"publisher":{"@id":"https:\/\/www.cryptometer.io\/news\/#organization"},"image":{"@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg","articleSection":["Altcoins","Featured","General News"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/www.cryptometer.io\/news\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/","url":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/","name":"Solana Devs Resolve Confidential Token Exploit Risk","isPartOf":{"@id":"https:\/\/www.cryptometer.io\/news\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg","datePublished":"2025-05-05T11:50:06+00:00","dateModified":"2025-05-05T11:50:09+00:00","description":"Solana developers and validators have patched a severe zero-day vulnerability that could have allowed attackers to mint unlimited Token-22 confidential","breadcrumb":{"@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#primaryimage","url":"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg","contentUrl":"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg","width":800,"height":499,"caption":"solana"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cryptometer.io\/news\/solana-devs-resolve-confidential-token-exploit-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cryptometer.io\/news\/"},{"@type":"ListItem","position":2,"name":"Solana Devs Resolve Confidential Token Exploit Risk"}]},{"@type":"WebSite","@id":"https:\/\/www.cryptometer.io\/news\/#website","url":"https:\/\/www.cryptometer.io\/news\/","name":"CryptoMeter.io","description":"","publisher":{"@id":"https:\/\/www.cryptometer.io\/news\/#organization"},"alternateName":"CryptoMeter.io","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cryptometer.io\/news\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cryptometer.io\/news\/#organization","name":"CryptoMeter.io","url":"https:\/\/www.cryptometer.io\/news\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cryptometer.io\/news\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.cryptometer.io\/news\/wp-content\/uploads\/2023\/01\/cropped-favicon_large.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.cryptometer.io\/news\/wp-content\/uploads\/2023\/01\/cropped-favicon_large.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"CryptoMeter.io"},"image":{"@id":"https:\/\/www.cryptometer.io\/news\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/CryptoMeterIO"],"publishingPrinciples":"https:\/\/www.cryptometer.io\/news\/about-us\/"},{"@type":"Person","@id":"https:\/\/www.cryptometer.io\/news\/#\/schema\/person\/294f2836271d1655ea8e2e5619466eb8","name":"Manjeet Mane","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/496227b2ca2c6045749260e74082028192b686959152b44fa23f9c0751c7781a?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/496227b2ca2c6045749260e74082028192b686959152b44fa23f9c0751c7781a?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/496227b2ca2c6045749260e74082028192b686959152b44fa23f9c0751c7781a?s=96&d=retro&r=g","caption":"Manjeet Mane"},"description":"Manjeet Mane, an accomplished developer in cryptocurrency and blockchain technology, has devoted years to advancing these fields. With a firm belief in their transformative power across industries, he specializes in full-stack development.","url":"https:\/\/www.cryptometer.io\/news\/author\/manjit\/"}]}},"jetpack_featured_media_url":"https:\/\/www.cryptometer.io\/news\/wp-content\/uploads\/2024\/03\/solana.jpg","_links":{"self":[{"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/posts\/14460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/comments?post=14460"}],"version-history":[{"count":1,"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/posts\/14460\/revisions"}],"predecessor-version":[{"id":14462,"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/posts\/14460\/revisions\/14462"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/media\/3635"}],"wp:attachment":[{"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/media?parent=14460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/categories?post=14460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptometer.io\/news\/wp-json\/wp\/v2\/tags?post=14460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}