NEW: Unlock the Future of Finance with CRYPTO ENDEVR - Explore, Invest, and Prosper in Crypto!
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
No Result
View All Result

Post Mortem: ZK ElGamal Proof Program Bug

Post Mortem: ZK ElGamal Proof Program Bug
Share on FacebookShare on Twitter

Rewrite the

Timeline

On 2025-04-16, a potential vulnerability was reported to the Anza Github Security Advisory. The report contained a proof of concept for the vulnerability. There is no known exploit of the vulnerability. Engineers from Anza, Firedancer, and Jito began evaluating the report and confirmed that it allowed for the construction of arbitrary proofs that the ZK ElGamal Proof program would accept as valid. Engineers created a patch to address the reported issue. Additionally, engineers engaged security firms Asymmetric Research, Neodyme, and OtterSec to review the patch and provide support during the incident.

On 2025-04-17 at approximately 18:00 UTC, the Solana Foundation and Jito teams began to contact validator operators directly to distribute the patch. At approximately 23:00 UTC on the 17th, it was determined that a second patch was needed to address a similar issue in another area of the code base. The second patch was also reviewed by security firms and subsequently distributed to validator operators. At approximately 20:00 UTC on 2025-04-18, it was determined that more than a super majority of stake had adopted the patch. The patch was announced publicly in Discord here at 21:01 UTC. The cluster has now adopted the patch, and no funds are at risk.

Preliminaries

A Token-2022 confidential transfer is executed via two programs: the Token-2022 program and the ZK ElGamal Proof program. The Token-2022 program is a popular on-chain program that handles the main application logic for token mints, and accounts. The ZK ElGamal Proof program is a native program that verifies the correctness of complex zero-knowledge proofs certifying the validity of encrypted balances in accounts and transactions.

Typically, a zero-knowledge proof system is implemented by converting a two-party interactive zero-knowledge proof protocol into a non-interactive proof system using the “Fiat-Shamir Transformation”. The Fiat-Shamir Transformation specifies how a prover can generate public randomness using a cryptographic hash function. When verifying proofs generated via the Fiat-Shamir Transformation, the verification logic must hash all algebraic components comprising the proof.

The bug

In the on-chain ZK ElGamal Proof program, some algebraic components were not included in a hash used to generate a transcript for the Fiat-Shamir Transformation. A sophisticated attacker could use these unhashed components to develop a forged proof of an unauthorized action that passes verification. This vulnerability only affects Token-22 confidential tokens and allows an attacker to perform unauthorized actions such as minting unlimited tokens or withdrawing tokens from any account.

The patch

The ZK ElGamal Proof program has now been patched. Patched versions include:

The patch was added in this commit. The patch commit has been reviewed by Asymmetric Research, Neodyme, and OtterSec. Additionally, the ZK ElGamal Proof program had previously been audited. A full report is available here. Since the bug was confined to the ZK ElGamal Proof program, no updates were required for the Token-2022 program. All funds are safe, and there is no known exploit of the potential vulnerability.

tl;dr

A potential vulnerability was responsibly reported which could allow an attacker to forge an invalid proof and have it accepted by the ZK ElGamal Proof program. The ZK ElGamal Proof program has been patched and the patch has been adopted by Solana validator operators. There is no known exploit of the issue.

in well organized HTML format with all tags properly closed. Create appropriate headings and subheadings to organize the content. Ensure the rewritten content is approximately 1500 words. Do not include the title and images. please do not add any introductory text in start and any Note in the end explaining about what you have done or how you done it .i am directly publishing the output as article so please only give me rewritten content. At the end of the content, include a “Conclusion” section and a well-formatted “FAQs” section.

cryptoendevr

cryptoendevr

Related Stories

DFlow Prediction Markets API: Tokenizing the Future with Kalshi

DFlow Prediction Markets API: Tokenizing the Future with Kalshi

December 1, 2025
0

Rewrite the Today, we are releasing the DFlow Prediction Markets API, the first tokenization layer bringing Kalshi’s prediction markets to...

Bitcoin, Ethereum, XRP, Dogecoin, Litecoin, and Solana Cloud Mining Platform — Hashj Introduces Worldwide Access to the finest Crypto Mining Systems with Advanced Bitcoin Miner, ETH Miner, XRP Miner, and Dogecoin Miner capabilities as well as a 8 – CoinCentral

Bitcoin, Ethereum, XRP, Dogecoin, Litecoin, and Solana Cloud Mining Platform — Hashj Introduces Worldwide Access to the finest Crypto Mining Systems with Advanced Bitcoin Miner, ETH Miner, XRP Miner, and Dogecoin Miner capabilities as well as a $118 – CoinCentral

October 22, 2025
0

Rewrite the Bitcoin, Ethereum, XRP, Dogecoin, Litecoin, and Solana Cloud Mining Platform — Hashj Introduces Worldwide Access to the finest...

Introducing Solana Bench: How well can LLMs build complex transactions?

Introducing Solana Bench: How well can LLMs build complex transactions?

September 20, 2025
0

Rewrite the Introducing Solana BenchAt the Solana Foundation, we want to fund open-source AI tooling that measurably improves how developers...

Robot AI: blockchain’s breakout AI use case?

Robot AI: blockchain’s breakout AI use case?

September 20, 2025
0

Rewrite the Autonomous VehiclesBy the end of 2025, a fleet of connected vehicles could generate 10 exabytes of data globally...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Melanie Shapiro

Melanie Shapiro

January 4, 2026
BitMine Stakes B Ether, Corporations Seek Crypto Yield

BitMine Stakes $1B Ether, Corporations Seek Crypto Yield

January 3, 2026
Mark Burgunder

Mark Burgunder

January 3, 2026
Bitcoin Price Remains Close to K as Trump Claims Maduro Was Captured: Weekend Watch

Bitcoin Price Remains Close to $90K as Trump Claims Maduro Was Captured: Weekend Watch

January 3, 2026
Peter Klamka

Peter Klamka

January 3, 2026

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

CRYPTO ENDEVR

About Us

Crypto Endevr aims to simplify the vast world of cryptocurrencies and blockchain technology for our readers by curating the most relevant and insightful articles from around the web. Whether you’re a seasoned investor or new to the crypto scene, our mission is to deliver a streamlined feed of news and analysis that keeps you informed and ahead of the curve.

Links

Home
Privacy Policy
Terms and Services

Resources

Glossary

Other

About Us
Contact Us

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

© Copyright 2024. All Right Reserved By Crypto Endevr.

No Result
View All Result
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms

Copyright © 2024. All Right Reserved By Crypto Endevr