The Solana Foundation has confirmed that a zero-day vulnerability that allowed an attacker to potentially mint certain tokens and even withdraw those tokens from user accounts has been fixed. A May 3 post-mortem from the Solana Foundation said that the security vulnerability, first discovered on April 16, could have allowed an attacker to forge an invalid proof affecting Solana’s privacy-enabling “Token-22 confidential tokens. ”There is no known exploit of the vulnerability, and Solana validators have since adopted the patched version, the foundation said. Solana zero-day security bug affected Token-22 confidential tokensThe Solana Foundation said the security vulnerability concerned two programs: Token-2022 and ZK ElGamal Proof
source: https://cointelegraph.com/news/solana-devs-validators-fix-critical-bug-criticism-mounts?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound