2025 年 6 月,我们发现了 solana 的 zk elgamal 证明程序中的一个关键的可靠性漏洞。 该漏洞允许恶意证明者伪造一个 sigma or 证明,绕过保密传输中的费用验证。 通过利用此缺陷,. Solana developers patched up a zk elgamal proof program bug, which could have allowed a hacker to mint unlimited tokens and withdraw them from user accounts. In this post, we explain the origin of the bug, the structure of sigma or proofs, how this particular omission led to a break in soundness, and the broader lessons it reveals for.