TL;DR
In April 2025, experts discovered a critical vulnerability in the ZK ElGamal Proof module tied to the Token-2022 program.
The threat involved the possibility of forging ZK proofs, enabling unauthorized minting or withdrawal of tokens.
Anza, Jito, and Firedancer quickly issued a patch, adopted by a supermajority of validators by April 18.
The fix was deployed quietly, sparking debate over decentralization in the community.
The vulnerability was eliminated. No losses or exploits occurred. All funds are safe.
Solana showcased maturity both in its tech stack and governance.
In mid-April 2025, the Solana Foundation and Jito teams stumbled upon a concerning discovery: a critical vulnerability in the ZK ElGamal Proof program, which handles private token transfers under Token-2022.
https://x.com/H8KUcom/status/1918942205370404958
ZK ElGamal Proof is a module that validates encrypted balances using zero-knowledge proofs.
The issue was insidious: during Fiat-Shamir Transformation, some algebraic proof components weren’t hashed. This opened the door for a technically sophisticated attacker to forge proofs and:
mint unlimited tokens,
withdraw funds from any account,
and do it all — without leaving a trace.
April 16: Anza documents the bug and posts a PoC to GitHub Security Advisory.
Same day: Jito and Firedancer join the review. Vulnerability confirmed.
April 17, 18:00 UTC: initial patch distribution to validators begins.
23:00 UTC: a similar issue is found elsewhere in the code — a second patch is released.
Audit & Review: fixes are audited by Asymmetric Research, Neodyme, and OtterSec.
April 18, 20:00 UTC: more than 66% of stake already upgraded.
21:01 UTC: incident resolution is publicly shared on Discord.
No exploit of the vulnerability was found in the wild.
Agave: ≥ v2.1.21, ≥ v2.2.11
Jito-Solana: ≥ v2.1.21-jito, ≥ v2.2.11-jito
Firedancer: ≥ v0.411.20121
"Since the bug was confined to the ZK ElGamal Proof program, no updates were required for the Token-2022 program. All funds are safe, and there is no known exploit of the potential vulnerability," confirmed Solana Foundation.
The way the patch was distributed stirred controversy. Instead of a public fix announcement, Solana coordinated privately with key validators (over 70%) to implement the fix quietly.
"This raises serious concerns — such ‘zero days’ threaten openness and decentralization," one user noted.
Solana co-founder Anatoly Yakovenko responded swiftly:
https://x.com/aeyakovenko/status/1919013298248560901
Read. Solana Inside: SOL ETFs, $500M Bonds, 1inch Joins, Decentralization & More
Solana: 1,212 active validators

Ethereum: 17,983 nodes (11,804 using Geth)

Staked supply:
Ethereum — 28%
Solana — 65%
Takeaway: Despite having fewer nodes, Solana shows 2.3x higher staking engagement.
Fidelity and JPMorgan openly call Solana a serious Ethereum contender. Why? Lightning-fast incident response, strong security practices, and deep validator engagement.
Solana faced a real-world crisis — and passed with flying colors. No testnet simulation, no theory. Just swift, calm, and effective action. No panic. No losses.
That’s what a mature ecosystem looks like.
🚀Curious? Follow us on X (Twitter) for crypto insights and sharp project picks!

