Content pfp
Content
@
0 reply
0 recast
0 reaction

Varun Srinivasan pfp
Varun Srinivasan
@v
Warpcast Fix: Wallet Verifications @horsefacts.eth patched a Warpcast issue last night that allowed someone to connect their wallet to your fid under some conditions. 

 To the best of our knowledge, no one took advantage of the issue on Warpcast before we fixed it. Thanks to @0xsec.eth for reporting this!
16 replies
14 recasts
163 reactions

Varun Srinivasan pfp
Varun Srinivasan
@v
If you want to verify a wallet on Warpcast.com, it creates a url where you can submit a signature from your wallet. Warpcast counter signs this with the signer it has for your account. The problem is that the submission url is predictable and wasn't closed when the verification was submitted. So someone watching the hubs for your verification could “back run” and post their own wallet verification to that URL, and Warpcast would have counter signed it with your signer, adding both wallets.
5 replies
2 recasts
57 reactions

Lokesh Thangam  pfp
Lokesh Thangam
@lokeshthangam
Great explanation of the issue! It’s important to stay aware of vulnerabilities like this. Glad it was caught and patched, but it's a good reminder to stay vigilant about security practices. Thanks for sharing the details!
0 reply
0 recast
0 reaction