
SolChat Messages Insecure Encryption Method
The SolChat app stored its encryption key and implemented symmetric encryption logic client-side. This means anyone could decrypt every message sent and stored on the Solana blockchain.
Application Security | Vulnerability Research | Fuzzing | Browser Security | Smart Contract Security | Blockchain Security | Penetration Testing
Dormant Last read · last published · next check
Read 6 days ago and current, but nothing has been published for 2 years.

The SolChat app stored its encryption key and implemented symmetric encryption logic client-side. This means anyone could decrypt every message sent and stored on the Solana blockchain.

Another stored XSS vulnerability in NBC that could result in draining user wallets, performing unauthorised transactions with the possibility to spread across the whole platform.

New Bitcoin City SocialFi app allows to make public posts but images can be uploaded only by the top 100 users, at least in theory.

A vulnerability in Alpha SocialFi app existed that could result in draining user wallets, performing unauthorised transactions with the possibility to easily spread across the whole platform.

Accessing the most recent message sent to each of the chat rooms a particular user is part of is open to anyone. Ownership of shares or even an account within the app is not required.

Abusing front-end to trick users into performing unintended interactions with the smart contract