Worldcoin Vulnerability: Blockchain Security Firm Exposes Unverified Orb Operator Access

2023-8-5 22:10

Blockchain security company CertiK recently revealed a serious flaw that put the Worldcoin system at serious risk. The system’s security and integrity might have been compromised if the vulnerability allowed Orb operators unrestricted access.

Users’ iris information was collected as part of Worldcoin’s Orb activities, necessitating a strong verification process to guarantee that only reputable businesses are in charge of the operations.

The system’s fault, however, made it possible for bad actors to get through the rigorous verification process without fulfilling the requirements.

Following the usual whitehat disclosure process, CertiK quickly informed the Worldcoin security team of the vulnerability.

Prompt Patching: Addressing The Vulnerability

Worldcoin has provided a patch to address the vulnerability in a prompt manner as a response to the threat. Attackers were unable to exploit the vulnerability due to the swift action taken.

Although CertiK acknowledged that the remedy effectively reduced the threat, they chose to reserve further information regarding the vulnerability and its mitigation for a later time.

This choice was probably intended to stop potential attackers from learning about the vulnerability before most users had a chance to upgrade their systems.

Worldcoin had only published reports on security audits conducted by Nethermind and Least Authority a week prior to the discovery of this vulnerability. These audits sought to find code flaws and strengthen defenses against intrusions.

Some 26 issues were found by Nethermind’s audit that needed to be addressed, and 24 of these were quickly resolved by Worldcoin during the verification phase. One of the remaining two problems was reduced, while the other was noted.

Six remedies were proposed by Least Authority to tackle th three challenges, all of which were either handled by Worldcoin or were planned to be addressed.

Worldcoin Confirms Flaw, No Real-World Attacks

Worldcoin confirmed the alleged flaw but stressed that it had not been used in any real-world attacks. They stressed that the vulnerability never provided access to Orbs or data, and that the manual review process for creating operator accounts for Orbs was never circumvented.

The fact that Worldcoin was able to address the problem within 24 hours of its discovery showed how dedicated they were to upholding the protocol’s security.

Even after the public debut of Worldcoin was initially a success, with favorable token prices and high enrollment rates, the project remained divisive because of worries that one business would have complete control over huge quantities of user personal information.

Meanwhile, criticism of the potential effects on data privacy and security was made by individuals like US National Security Agency whistleblower Edward Snowden and Ethereum co-founder Vitalik Buterin.

Concerns about the project’s potential for amassing enormous amounts of personal data that could be used for illicit activities have legitimately sparked concerns about the ethical issues surrounding such cutting-edge identification and financial networks.

Featured image from Worldcoin

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

SherLOCK Security (LOCK) на Currencies.ru

$ 0.1387 (+1.71%)
Объем 24H $13
Изменеия 24h: 10.06 %, 7d: -33.06 %
Cегодня L: $0.1387 - H: $0.1387
Капитализация $0 Rank 3458
Доступно / Всего 0 LOCK / 4.969m LOCK

security access worldcoin serious blockchain orb vulnerability

security access → Результатов: 126


Revolutionary Collaboration: MetaMask Institutional and Fireblocks Unite to Provide Unparalleled DeFi and Web3 Opportunities for Institutional Investors and Builders

ConsenSys and Fireblocks have joined forces to provide institutional investors and builders with unparalleled access to decentralized finance (DeFi) and Web3. By integrating MetaMask Institutional (MMI), an enterprise-grade web3 wallet, with Fireblocks’ platform for blockchain product development and crypto operations management, they offer a comprehensive solution for wallet security, portfolio management, and connectivity to over […] Сообщение Revolutionary Collaboration: MetaMask Institutional and Fireblocks Unite to Provide Unparalleled DeFi and Web3 Opportunities for Institutional Investors and Builders появились сначала на Coinstelegram.

2023-6-9 16:30


Фото:

The Recent LastPass Hack Showcases Web2’s Security Limitations… Here’s What Needs to Change

Popular password management service LastPass revealed in a December 23 statement that it had been on the receiving end of a major hack last August. As a result, miscreants were able to make their way into several encrypted passwords, which could potentially be cracked through a technique called ‘brute force guessing,’ giving them access to […]

2023-2-22 16:36


Фото:

DeFi-Focused Crypto Wallet Ambire Now Out Of Beta

After undergoing extensive auditing and beta testing with more than 5,000 accounts, the first non-custodial wallet with email authentication, Ambire Wallet has been launched to the public. Ambire wallet is a new-generation non-custodial and open-source smart wallet that offers its users easy access to DeFi enhanced user experience and a focus on security. Ambire is […]

2021-12-17 23:52


iTrustCapital Gains Security Boost with Coinbase Custody Integration

Cryptocurrency retirement savings platform iTrustCapital has announced it is integrating Coinbase Custody services to provide its clients with an additional layer of security. iTrustCapital provides IRAs (individual retirement accounts) and other qualified retirement funds with 24/7 access to digital cryptocurrency assets and precious metals through its tax-advantaged, IRS compliant, trading platform. The new integration helps […]

2021-6-18 21:10


Фото:

State-Owned Swiss Bank Postfinance Launches App Supporting 13 Cryptocurrencies

The banking subsidiary of the national postal service of Switzerland, Postfinance, has launched a mobile app providing clients with access to cryptocurrencies, ETFs and more. The software allows users to make payments, save funds or invest in various assets, with a commitment to a level of security provided only by the country’s leading online banks. […]

2021-5-14 03:30


NTT, FATH Mechatronics and peaq partner on next-gen blockchain data center security solution

NTT Global Data Centers EMEA has brought FATH Mechatronics and peaq together to create and integrate an innovative access control solution for data centers. The security solution combines FATH’s IoT hardware with peaq’s blockchain-based access control software, a permission and access control system which leverages blockchain to improve cybersecurity and optimize access management processes.

2020-12-10 21:25


Фото:

Ethereum Classic Undergoes Thanos Hard Fork Upgrade for Improved GPU Miner Access

After crossing the 11. 7 million block height milestone, Ethereum Classic (ETC) has undergone a hard fork to bring about the anticipated Thanos upgrade. The Ethereum fork has suffered numerous security issues with multiple 51% attacks and proponents are hoping the new Thanos upgrade will provide much-needed network fidelity while allowing GPU-based mining to continue.

2020-11-30 18:01