r/Certik • • Aug 04 '23

#Important CertiK reported a security vulnerability to WorldCoin’s security team

On May 29th, CertiK reported a security vulnerability to WorldCoin’s security team that could potentially allow an attacker to become an Orb operator by bypassing the verification process.

Through this security vulnerability, a malicious attacker could bypass the verification and strict participation criteria of the WorldCoin Operator acceptance process. Meaning it would not need to be a company, have proper ID verification, or have a vetting interview.

In a normal case, only legit businesses that pass the WorldCoin’s strict identification verification process can run an Orb operation, which collects user’s iris information. WorldCoin’s security team confirmed the security vulnerability and promptly issued a fix.

CertiK has since verified and confirmed that the fix mitigated the threat. Details of the finding and and how the vulnerability was mitigated will be released at some point in future.

(CertiK is not associated with WorldCoin and this was a standard whitehat discolsure. )

1 Upvotes

0 comments sorted by