Solana network team has addressed a critical security vulnerability
The incident was not publicly announced until after the upgrade was installed by the vast majority of validators
09.08.2024 - 09:00
114
2 min
0
What’s new? The Solana team, as well as validators and blockchain client developers, fixed a critical security vulnerability. On August 7, representatives from the Solana Foundation NPO contacted operators known to them through private channels to covertly address the vulnerability and prevent an exploit.
What else is known? The availability of the patch in a repository on GitHub allowed operators to independently test and deploy it. By August 8, implementation instructions had been sent to Solana participants, protecting 66,6% of the network.
The vulnerability was publicly reported after 70% of the network participants had installed the patch. Thus, developer Solana Labs published an announcement in the Discord channel, where it urged the remaining operators to update their systems.
“The key is to manage to contact enough stake to protect the network while retaining confidentiality. The amazing thing about Solana’s validator community is that it’s very active and engaged, and even if you don’t directly know a validator they’re often only one degree of separation away as we’ve all made friends with others over the years,” writes the team at Laine, the company that manages the Solana validator.
Earlier, the Solana team launched a rewards program with amounts up to $1 million for finding vulnerabilities in the upcoming Firedancer upgrade. This validator client, created by the Jump Crypto market maker team, is designed to improve Solana’s fault tolerance. In the past years, the blockchain has experienced multiple failures due to congestion.
Currently, it is the fastest blockchain among both the first (L1) and second (L2) layer networks, according to analysts at CoinGecko. The record was set at 1054 transactions per second (TPS).
In April, developers of the Cosmos blockchain ecosystem eliminated a $126 million vulnerability discovered by Asymmetric Research auditors as part of the bug bounty program.
Useful material?
Incidents
Scammers took advantage of the former US president’s recent announcement of a real DeFi protocol
Sep 4, 2024
Technologies
The upgrade is aimed at implementing a new decentralized project governance system
Sep 2, 2024
Incidents
The company placed $2б4 billion in bonds maturing in 2026, but their value has fallen dramatically since the entrepreneur’s arrest
Aug 30, 2024
Incidents
In both cases, depending on the outcome of the investigations, the messenger could be blocked
Aug 29, 2024
Market
The project will offer a decentralized alternative to traditional banking services
Aug 29, 2024
Trends
Within a week of its launch, the platform managed to overtake its main competitor, Pump.fun on the Solana network
Aug 28, 2024