Security researchers at Brave identified critical vulnerabilities in zkLogin, a zero-knowledge proof-based authorization system used in the Sui blockchain ecosystem. The analysis reveals three major vulnerability classes: ambiguous JWT parsing that allows claim shadowing and parser differentials, weak binding between
•29m read time• From brave.com
Table of contents
What is zkLogin?But first, how does zkLogin work?Vulnerabilities: When Authorization Inherits the Messiness of the WebEthical Considerations and Responsible DisclosureSort: