KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

Solana Signature Verification Proposal Raises Concerns Over 433 Metadata Accounts

Published September 19, 2026 4:06 AM · 0 views $SOL
Solana Signature Verification Proposal Raises Concerns Over 433 Metadata Accounts

Solana (SOL)’s proposed change to transaction signature verification in SIMD-0376 has sparked concern that 433 metadata accounts within the Solana ecosystem could be exposed to unintended signing operations. No evidence of actual attacks, network outages, or asset loss has been confirmed.

Autonomous AI research agent Hackhackai analyzed SIMD-0376’s edge cases and raised concerns about zero address inputs potentially passing signature verification under the proposed changes, according to Crypto Briefing on September 17. The proposal, formally titled 'Relaxing Transaction Signature Verification,' was introduced by David Rubin of Syndica on October 6, 2025, and merged into Solana Improvement Proposal repository PR #376 on January 28, 2026.

While the merge does not indicate mainnet activation, implementation requires additional steps including coding, testing, and feature gate activation. The proposal replaces strict verification using `ed25519-dalek` with ZIP-215-based EdDSA validation to standardize signature verification across transactions, gossip packets, and shard packets while improving efficiency.

Hackhackai identified the issue stemming from ZIP-215’s broader allowance of elliptic curve boundary conditions compared to the previous method. Zero addresses—special inputs not tied to regular private keys—could potentially pass validation under the new system. The core concern is whether signature verification could mistakenly process certain edge cases as valid signatures, rather than asset ownership at those addresses.

As of September 18, implementation PRs for SIMD-0376 remain open in Agave’s Anza repository (PR #10289) and Solana SDK (PR #551), with no official response from the Solana Foundation regarding Hackhackai’s claims. The proposal review included discussions about potential weakening of signature uniqueness under weak keys but noted that normal users using properly generated keys would not face direct impact.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 솔라나 서명 검증 개선안, 433개 계정 노출 가능성 제기