i found and responsibly disclosed two critical account takeover bugs in @octra's webcli, the browser-based wallet
one needed a single click. the other needed zero
both could sign and broadcast transfers out of a victim's wallet
huge thanks to @octralex and @lambda0xE at @octra for the fast response and coordination throughout
this is what makes the network more secure
just to reiterate: this was an implementation bug in the ZK verification path used when releasing encrypted balances, not a break of HFHE, ristretto, or octraโs encrypted computation layer.
ZK was an auxiliary proof layer rather than part of octraโs native cryptographic design. the incident reinforced our decision to replace that spend-proof path with TAPE, a verifier designed around octraโs own FHE field core. the update is since underway.
excellent technical write-up, and thank you again for the responsible disclosure!
really appreciate how quickly the @octra team handled this!
huge thanks to @octralex and @lambda0xE for working through the issue during the night, patching it within hours
also big thanks to @zellic_io and @proofofk for helping me getting in contact with the @octra team so quickly
full technical writeup:
https://t.co/XhAHMrQ2iD
๐24 hours into the CTF, 24 hours left!
Huge thanks to @osec_io, @rivsec and @EPT_gg for all the support ๐ค
We just released some new challenges, and here are some cool stats to look at ๐
We're happy to announce that @osec_io and @rivsec will sponsor our CTF on the 29th of August! The CTF would not be possible without them, as well as the infrastructure sponsored by @EPT_gg - thanks for all the support!๐ค
UHI5 hookathon results are in!
Congratulations to these devs for winning the @inkonchain prize ๐
โข YOLO Protocol: @AlvinYap510
โข kvhook: @daniel__boye