Varun Srinivasan pfp
Varun Srinivasan

@v

If you want to verify a wallet on Warpcast.com, it creates a url where you can submit a signature from your wallet. Warpcast counter signs this with the signer it has for your account. The problem is that the submission url is predictable and wasn't closed when the verification was submitted. So someone watching the hubs for your verification could “back run” and post their own wallet verification to that URL, and Warpcast would have counter signed it with your signer, adding both wallets.
2 replies
15 recasts
28 reactions