Content
@
0 reply
0 recast
0 reaction
Le Hash
@hazae41
GM 🫡 Are you ready to see one of the most stupid vulnerability you will ever see in crypto space? Here is the first vulnerability I found about the WalletConnect's Verify API 👇
1 reply
1 recast
1 reaction
Le Hash
@hazae41
They have already pushed a fix, so I guess I can explain it now, and you can share it too 😎 https://github.com/WalletConnect/walletconnect-monorepo/commit/0d42d705f658f4da031fc69cb3411ab77b8b976b
1 reply
0 recast
1 reaction
Le Hash
@hazae41
Here is a live demo 🔥 Click on the following links and try to connect the former with the latter wc-exploit-1.vercel.app wc-wallet.vercel.app Here is what you should see with and without the exploit Hola, Pancakeswap 👋
1 reply
0 recast
1 reaction
Le Hash
@hazae41
So how does it work? The dapp can simply tell the wallet: "I swear I am legit, here is a server that will say I'm legit" 🫣 (and of course, the server is owned by the same person — the attacker ) Yes, that's the vulnerability 🤡
1 reply
0 recast
1 reaction