Monero unlock_time issue
#33
tsusanka
announced in
Past Security Issues
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Details
The Monero field unlock_time was not confirmed on the device's display. Since Monero network does not do any sanity checks for this field, this allows a perpetrator to lock userβs funds for a very long time by simply setting it to a very high value.
Fix
trezor/trezor-firmware@7944c1a
Read more
Official blogpost
Beta Was this translation helpful? Give feedback.
All reactions