Zodiac Discloses Security Flaw in ERC-1271 Verification Logic

iconKuCoinFlash
Share
AI summary iconSummary
On June 20 (UTC+8), Zodiac disclosed a security vulnerability in its ERC-1271 verification logic, attributing it to a flaw in the Roles Modifier module. The issue permitted attackers to bypass authentication by exploiting a signature validation weakness in which only the "magic value" was verified. The incident underscores the importance of enhanced CFT measures and aligns with upcoming MiCA compliance requirements. MetaEra confirmed the vulnerability and recommended immediate updates.

ME News reports that on June 20 (UTC+8), the Zodiac team released a security incident analysis report regarding the Zodiac Roles Modifier, disclosing that the root cause of the vulnerability lies in a flaw in the ERC-1271 transaction signature verification logic: the system only checks the returned "magic value" to determine signature validity, without verifying whether the call itself succeeded, potentially allowing failed verifications to be misrepresented as valid signatures and bypassing the module authentication mechanism. (Source: ChainCatcher)

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.