Wu Shuo learned that the Brave research team released a report indicating that the security and privacy risks of the blockchain transaction authorization system zkLogin do not solely depend on the underlying zero-knowledge proofs. Instead, they heavily rely on a series of protocol-level assumptions that are not explicitly constrained, such as JWT/JSON parsing, issuer trust policies, issuance context binding, and execution environment integrity.


The paper summarizes three main vulnerabilities: loosely defined and non-standard claim extraction that may accept malformed JWTs; converting short-term authentication credentials into long-term authorization tokens without enforcing issuer/audience/subject/time binding, which can lead to cross-application misuse (especially in browser scenarios). It emphasizes that these issues are not inherent flaws in the cryptographic algorithms themselves.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin