Solana's Confidential Transfer Kill Switch: How It Works and What It Costs
Solana's Token-2022 confidential transfers rely entirely on the ZK ElGamal proof program, a separate on-chain program that verifies zero-knowledge proofs for every confidential operation. Two validator feature gates exist to disable and re-enable this program, and both have already been used: a flaw in the verifier's Fiat-Shamir transcript discovered on June 10, 2025 triggered a disable at epoch 805, with the program restored at epoch 982 in June 2026 after audits. When the proof program is disabled, public token balances continue functioning normally, but confidential balances are frozen in place — holders cannot deposit, transfer, or even withdraw back to plain balances until the program is re-enabled. No state migration is required upon re-enablement, as the underlying ElGamal ciphertexts remain intact in accounts throughout the outage. Developers should also note that the older ZK Token Proof program still exists as an address but is a non-functional stub that silently returns success without verifying anything, meaning any tooling still referencing it provides no actual proof validation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in