This is a segment of the LightSpeed Newsletter. Subscribe to read the full edition.
In mid-April, Solana’s world leader took him to X and posted the same mysterious hash. Such strings can hide the content of the message from the public, allowing anyone with the original data to see its credibility.
Some speculated that Hash is a way to tweak Solana Validators to patch vulnerabilities in Solana’s code. They turned out to be correct. A drawback of the protocol’s confidential token product is that a sophisticated attacker has allowed Mint Mint Mint with unlimited new tokens. The upgrade follows similar vulnerabilities and patch situations that fell in August.
Solana’s Token-2022 Standard includes a feature named “Confidential Transfers” that allows addresses to trade in Solana without revealing the amount of transfer. Confidential transfers are verified with zero knowledge proof. This bug was basically caused by some missing mathematics that could have allowed people to know who know to accept invalid proofs in Solana’s ZK program.
The bug identified with the help of Solana Validators and has since patched it personally has given Ethereum fans some good engagement baits, but to be fair, I’m not sure if Solana had a better option here. User funds were not lost, but this is definitely the most important factor.
“Criticism of Solana’s zero-day bug fixes makes me realize I don’t know how it works in Ethereum,” wrote Mika Honkasaro, balanced investment partner, about X.
One person involved in Solana’s efforts to patch bugs said that the process of personally patching a bug before publicly revealing the vulnerability continues with “established security protocols found in other major blockchain and software projects.”
Also, Solana Balidators are not sharing war plans over signal chats. The Solana Foundation, Anza and Jito contacted the validators via the platform patchwork and then spoke to them to be involved in the response, sharing a hash to prove that outreach was legal.
If you believe Solana is the financial rail of the future, it is actually a rather nasty way to tune emergency software updates. Solana’s approach to this kind of thing is, at least, at least a little too distributed.
Discover more from Earlybirds Invest
Subscribe to get the latest posts sent to your email.