We believe privacy shouldn't require trust.
That's why we've open-sourced the zkVoid Proof Service, the backend infrastructure that powers $cSOL & $VOID transactions.
https://t.co/LTTZbhWbu0
On June 10, 2025 a potential security vulnerability was reported to the @anza_xyz Github Security Advisory by @suneal_eth, a security researcher from @zksecurityXYZ. The issue has been mitigated on all Solana clusters and all funds are safe. More details below 👇
As we await the re-establishment of confidential transfers / ElGamal program for token2022 we will begin a transition.
Starting Monday, June 30th we will continue development on the next phase of an independent privacy protocol powered by ZK proofs / Snarks.
🤟🏽
@johnny_bra82035@arcium It worked when the token was launched.
Due to a security issue the elGamal program was disabled by Solana rendering the confidential transfer token extension useless until it is fixed.
While we continue to wait on the status of token2022 / ElGamal program, we continue to build out product plans.
We have some features ready for release in the event El Gamal comes back.
If not, we are prepared to pivot and make the necessary changes to provide confidentiality.
new zk elgamal vulnerability was apparently found, no official details yet, but there's already a patch to temporarily gate the feature on 2.2.16 (upgrade you damn fools!)
this one program is giving anza a load of fun
$cSOL & $VOID are safe from this vulnerability.
Thank you everyone for your patience in this downtime as we await restoration of confidential transfer extension usage on mainnet. 🫡
@TheMisterFrog@trentdotsol A missing term in that Fiat-Shamir transcript (the “ZK ElGamal Proof” program) let attackers forge proofs—meaning unlimited counterfeit mints and forced withdrawals until now.
This vulnerability was only for token-2022 with the confidential setting on. (Can’t think of any)
Open Source proof generation for ZK confidential transfers. True privacy depends on it.
The trusted backend model is great for non-custodial transfers, but doesn't foster a trustless environment.
Open source enables anyone to host their own proof service.
An upgrade to the token2022 program has created failure in confidential instructions.
Services are suspended for confidential operations until a disclosure is made by @solana team in regards to what changes they've made to the program.
Sorry for the inconvenience.
@solana_devs Was wondering if we'll see an update in documentation for the confidential balance token extension.
An upgrade to the token-2022 program yesterday seems to have changed the way the extensions deposit, apply, withdraw, and transfer instructions work.
https://t.co/LcDq5MPxgK
An upgrade to the token2022 program has created failure in confidential instructions.
Services are suspended for confidential operations until a disclosure is made by @solana team in regards to what changes they've made to the program.
Sorry for the inconvenience.