Security researchers at Brave identified critical vulnerabilities in zkLogin, a zero-knowledge proof-based authorization system used in the Sui blockchain ecosystem. The analysis reveals three major vulnerability classes: ambiguous JWT parsing that allows claim shadowing and parser differentials, weak binding between

29m read time From brave.com
Post cover image
Table of contents
What is zkLogin?But first, how does zkLogin work?Vulnerabilities: When Authorization Inherits the Messiness of the WebEthical Considerations and Responsible Disclosure

Sort: