Futures
Access hundreds of perpetual contracts
TradFi
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Futures Kickoff
Get prepared for your futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to experience risk-free trading
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Launchpad
Be early to the next big token project
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Wu Shuo learned that the Brave research team released a report indicating that the security and privacy risks of the blockchain transaction authorization system zkLogin do not solely depend on the underlying zero-knowledge proofs. Instead, they heavily rely on a series of protocol-level assumptions that are not explicitly constrained, such as JWT/JSON parsing, issuer trust policies, issuance context binding, and execution environment integrity.
The paper summarizes three main vulnerabilities: loosely defined and non-standard claim extraction that may accept malformed JWTs; converting short-term authentication credentials into long-term authorization tokens without enforcing issuer/audience/subject/time binding, which can lead to cross-application misuse (especially in browser scenarios). It emphasizes that these issues are not inherent flaws in the cryptographic algorithms themselves.