Content pfp
Content
@
0 reply
0 recast
0 reaction

Varun Srinivasan pfp
Varun Srinivasan
@v
Warpcast Fix: Wallet Verifications @horsefacts.eth patched a Warpcast issue last night that allowed someone to connect their wallet to your fid under some conditions. 

 To the best of our knowledge, no one took advantage of the issue on Warpcast before we fixed it. Thanks to @0xsec.eth for reporting this!
16 replies
14 recasts
163 reactions

Varun Srinivasan pfp
Varun Srinivasan
@v
If you want to verify a wallet on Warpcast.com, it creates a url where you can submit a signature from your wallet. Warpcast counter signs this with the signer it has for your account. The problem is that the submission url is predictable and wasn't closed when the verification was submitted. So someone watching the hubs for your verification could “back run” and post their own wallet verification to that URL, and Warpcast would have counter signed it with your signer, adding both wallets.
5 replies
2 recasts
57 reactions

pharm.Ashley pfp
pharm.Ashley
@ashergregson
I found linking quite a hassle tho!!. I was unable to link any wallets at all Was that part of the glitch?
0 reply
0 recast
0 reaction