By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
IndebtaIndebta
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Notification Show More
Aa
IndebtaIndebta
Aa
  • Banking
  • Credit Cards
  • Loans
  • Dept Management
  • Mortgage
  • Markets
  • Investing
  • Small Business
  • Videos
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Follow US
Indebta > Markets > Crypto > Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access
Crypto

Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access

News Room
Last updated: 2023/08/05 at 1:14 PM
By News Room
Share
4 Min Read
SHARE

Blockchain security firm CertiK has disclosed a vulnerability in the Worldcoin protocol that allowed unauthorized access for an Orb operator. 

In a recent Twitter thread, CertiK explained that the vulnerability allowed anyone to bypass the verification requirements to become an Orb operator without meeting the necessary criteria, such as being a legitimate company or passing a vetting interview. 

“Through this security vulnerability, a malicious attacker could bypass the verification and strict participation criteria of the Worldcoin Operator acceptance process,” the company wrote. 

The usual process allows only legitimate businesses that pass strict identification verification to run an Orb operation, which collects users’ iris information. 

CertiK said it reported the issue to Worldcoin through a whitehat disclosure procedure, and the project’s security team quickly addressed the vulnerability with a fix.

“CertiK has since verified and confirmed that the fix mitigated the threat,” the company wrote.

Notably, CertiK’s disclosure comes just a week after Worldcoin released a report on security audits conducted by Nethermind and Least Authority. 

The audits covered various areas, including vulnerabilities in the code that could lead to adversarial actions and other attacks, as well as protection against malicious attacks and exploitation methods.

Nethermind’s audit identified 26 items during the security assessment, of which 24 were fixed after the verification stage, one was mitigated, and one was acknowledged.

On the other hand, Least Authority discovered three issues in the protocol and provided six suggestions, all of which have either been resolved or have planned resolutions, according to Worldcoin.

Worldcoin Faces More Issues Amid Kenya Suspension

Last week, Kenya’s Ministry of the Interior issued a decree suspending Worldcoin signup, citing concerns about its activities’ authenticity, legality, security, financial services, and data protection. 

In an official announcement, the ministry said relevant agencies had begun investigating the project.

“Relevant security, financial services and data protection agencies have commenced inquiries and investigations to establish the authenticity and legality of the aforesaid activities,” interior minister Kithure Kindiki said at the time.

Worldcoin, co-founded by OpenAI CEO Sam Altman and valued at over $2 billion, aims to create a “proof-of-personhood” network by registering verified humans through eyeball scans. 

The project has already received notable criticism since its debut. 

Since Worldcoin scans people’s irises and eyes to ensure that the crypto is distributed fairly, some have expressed privacy and security concerns. 

The collection of biometric data has also raised questions about how this sensitive information will be stored, protected, and potentially used.

Furthermore, some have questioned Worldcoin’s methods of obtaining consent. 

A 2022 investigation by MIT Review found that Worldcoin used deceptive marketing practices, collected more personal data than disclosed, and failed to obtain meaningful informed consent.

Just recently, it was revealed that European regulators, including the French National Commission on Informatics and Liberty (CNIL) and the Bavarian state authority in Germany, are collaborating with an investigation into the project. 



Read the full article here

News Room August 5, 2023 August 5, 2023
Share this Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Finance Weekly Newsletter

Join now for the latest news, tips, and analysis about personal finance, credit cards, dept management, and many more from our experts.
Join Now
Beyond Meat: Why this strategist has ‘no interest’ in this meme stock

Watch full video on YouTube

‘Ghost jobs’ are adding another layer of uncertainty to the stalling jobs picture

Watch full video on YouTube

Harbor Dividend Growth Leaders ETF Q3 2025 Commentary (GDIV)

Harbor Capital is an asset manager focused on curating an intentionally select…

Digital bank N26 appoints UBS executive as new chief after fresh sanctions

Unlock the Editor’s Digest for freeRoula Khalaf, Editor of the FT, selects…

Gold’s decline could be the start of a correction. 📉

Watch full video on YouTube

- Advertisement -
Ad imageAd image

You Might Also Like

Crypto

'Fundamental Shift' in Traditional Bitcoin Market Cycle May Be on the Horizon

By News Room
Crypto

FTX/Alameda Unstakes Over $1B in Solana – Is a Major Price Shift Coming?

By News Room
Crypto

Mastercard Launches “Crypto Credential” To Replace Wallet Addresses With Usernames

By News Room
Crypto

Polygon Executive Pivots Roles To Developing ZK Proof Tech

By News Room
Crypto

Altcoin Interest Driving South Korean Crypto Craze – Report

By News Room
Crypto

Russian Central Bank Flags Sharp Rise in Crypto-related Activity

By News Room
Crypto

BitGo’s $100M Suit Against Galaxy Gets Green Light from Delaware Supreme Court

By News Room
Crypto

Here Are Your Top Crypto Gainers Today on DEXScreener

By News Room
Facebook Twitter Pinterest Youtube Instagram
Company
  • Privacy Policy
  • Terms & Conditions
  • Press Release
  • Contact
  • Advertisement
More Info
  • Newsletter
  • Market Data
  • Credit Cards
  • Videos

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

I have read and agree to the terms & conditions
Join Community

2023 © Indepta.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?