Malicious change in mixed transactions #36
tsusanka
announced in
Past Security Issues
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Details
A specially crafted multisig transaction could leverage a ToCToU bug to include a change output of an attacker, which wasn't confirmed by the user.
Read more
Official blogpost
Beta Was this translation helpful? Give feedback.
All reactions