🍀 Spring Date with Fortune, Prizes with Raffle! Growth Value Phase 1️⃣ 7️⃣ Spring Raffle Carnival Begins!
Seize Spring's Good Luck! 👉 https://www.gate.com/activities/pointprize?now_period=17
🌟 How to Participate?
1️⃣ Enter [Square] personal homepage, click the points icon next to your avatar to enter [Community Center]
2️⃣ Complete Square or Hot Chat tasks such as posting, commenting, liking, speaking to earn growth value
🎁 Every 300 points can raffle once, 10g gold bars, Gate Red Bull gift box, VIP experience card and more prizes waiting for you to win!
Details 👉 https://www.gate.com/ann
吴說獲悉,Brave 研究團隊發布報告指出,區塊鏈交易授權系統 zkLogin 的安全與隱私風險並非僅取決於底層零知識證明,而高度依賴 JWT/JSON 解析、issuer 信任策略、發行上下文綁定與執行環境完整性等一系列協議層未明確約束的假設。
論文歸納三類主要漏洞:寬鬆且非規範的 claim 提取可能接受畸形 JWT;將短期認證憑證轉化為長期授權憑證但未強制 issuer/audience/subject/時效綁定,或導致跨應用冒用(尤其在瀏覽器場景),並強調上述問題均非加密算法本身缺陷。