Solana fixed a zero-day vulnerability, which could lead to unlimited issuance or theft of some tokens."
Online reports that the Solana Foundation announced that a serious "zero-day" vulnerability that affected confidential transmission capabilities on its network has been successfully fixed. The vulnerability was discovered on April 16, and the foundation immediately secretly organized verifiers to coordinate network updates and completed the repair work within two days. This vulnerability involves the ZK certification system used to verify the confidential transfer of Token-2022 standard tokens. If used, attackers could theoretically minte specific tokens indefinitely through forged certificates or steal these tokens from user accounts. The Solana Foundation said it did not disclose the vulnerability until the fix was completed to ensure security. There is currently no evidence that the vulnerability was actually exploited and all user funds are safe. At the same time, it was pointed out that although the confidential transfer function has been online for some time, the current adoption rate is not high.
Disclaimer: The views in this article are from the original Creator and do not represent the views or position of Hawk Insight. The content of the article is for reference, communication and learning only, and does not constitute investment advice. If it involves copyright issues, please contact us for deletion.