Skip to content

security: fix critical double-spend and unauthorized subscription resume#29

Open
Ishant5436 wants to merge 1 commit into
zonelessdev:mainfrom
Ishant5436:security/double-spend-and-sub-fix
Open

security: fix critical double-spend and unauthorized subscription resume#29
Ishant5436 wants to merge 1 commit into
zonelessdev:mainfrom
Ishant5436:security/double-spend-and-sub-fix

Conversation

@Ishant5436
Copy link
Copy Markdown

I have identified two critical security flaws in the payout logic and subscription program that permit systematic double-spending and unauthorized fund extraction by merchants.

A detailed report and recommended mitigations are included in security/VULNERABILITY_REPORT.md.

Verified via race-condition simulation and state-machine audit.

Settlement Information:

  • Solana: 2WktXRjaQ4GKhj6FJhUSndTBLVjxrk43TQwyywehneDA

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant