According to the official blog of Solana Foundation, security researchers have reported potential vulnerabilities in the ZK ElGamal Proof program to Solana ecosystem stakeholders. The report includes a proof of concept (PoC) of the vulnerability, and no exploitation of the vulnerability has been found so far. After evaluation, this vulnerability allows attackers to construct arbitrary proofs and bypass verification, affecting the token-2022 security token and enabling it to perform illegal operations such as unlimited minting. In order to respond in a timely manner, on June 11th, the relevant team updated the upgradable Token-2022 program and temporarily disabled the confidential transfer function. On June 13th, an urgent upgrade request was sent to Solana Technology Discord, requesting the operator to upgrade the software to disable the ZK ElGamal certification program. On June 19th, at the beginning of the mainnet beta epoch 805, the program was officially disabled through functional activation.
At present, the token-2022 function using ZK ElGamal is mostly used by innovative products in testing. Although mainstream stablecoins have initialized confidential transfers, they are not open to users, resulting in extremely low actual usage rates and minimal impact. After completing the audit and fixing the issues, the program will be reactivated, which is expected to take several months.