00ddf99d7771e87e7df384b4f2782a10d7516bf5
Three independent failures allowed an offline attacker with DB write access to sign transactions using a different wallet's private key: 1. evm_wallet had no HMAC envelope — aead_encrypted_id could be swapped silently. 2. AEAD used a static tag as AAD — any valid ciphertext decrypted as any wallet key. 3. No post-decryption check that the derived address matched the requested wallet. Fix: sign_entity covers (address, aead_encrypted_id) in a single transaction; CreateNew/Decrypt take caller-provided AAD (wallet address bytes); after decryption signer.address() is verified against the requested wallet address.
Arbiter
Policy-first multi-client wallet daemon, allowing permissioned transactions across blockchains
Security warning
Arbiter can't meaningfully protect against host compromise. Potential attack flow:
- Attacker steals TLS keys from database
- Pretends to be server; just accepts operator challenge solutions
- Pretend to be in sealed state and performing DH with client
- Steals user password and derives seal key
While this attack is highly targetive, it's still possible.
This software is experimental. Do not use with funds you cannot afford to lose.
Description
Languages
Rust
57.7%
Dart
39%
C++
1.1%
CMake
0.9%
Ruby
0.3%
Other
0.7%