🎉 #Gate Alpha 3rd Points Carnival & ES Launchpool# Joint Promotion Task is Now Live!
Total Prize Pool: 1,250 $ES
This campaign aims to promote the Eclipse ($ES) Launchpool and Alpha Phase 11: $ES Special Event.
📄 For details, please refer to:
Launchpool Announcement: https://www.gate.com/zh/announcements/article/46134
Alpha Phase 11 Announcement: https://www.gate.com/zh/announcements/article/46137
🧩 [Task Details]
Create content around the Launchpool and Alpha Phase 11 campaign and include a screenshot of your participation.
📸 [How to Participate]
1️⃣ Post with the hashtag #Gate Alpha 3rd
The Solana Foundation disclosed potential vulnerabilities in the ZK ElGamal Proof program and the measures taken to address them.
According to Gate News bot and reports from PaNewsLab, the Solana Foundation's official blog points out that security researchers have reported a potential vulnerability in the ZK ElGamal Proof program to stakeholders related to the Solana ecosystem. The report includes a proof of concept (PoC) of the vulnerability, and currently, no instances of the vulnerability being exploited have been found.
After assessment, the vulnerability allows attackers to construct arbitrary proofs and bypass verification, affecting the Token-2022 confidential token, enabling it to perform illegal operations such as infinite minting. To respond promptly, on June 11, the relevant team updated the upgradable Token-2022 program, first disabling the confidential transfer function. On June 13, an emergency upgrade request was sent to the Solana technical Discord, asking operators to upgrade the software to disable the ZK ElGamal proof program. On June 19, at the start of the mainnet-testnet epoch 805, the program was officially disabled through functionality activation.
Currently, the Token-2022 feature using ZK ElGamal functionality is primarily utilized by innovative products in testing. Although mainstream stablecoins have initialized private transfers, they are not open to users, resulting in a very low actual usage rate and minimal impact. The program will be re-enabled after completing audits and fixing issues, which is expected to take several months.