Contra - A professional network for the jobs and skills of the futureCritical IDOR Bug in Web3 Protocol Threatens User Privacy
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Critical IDOR Discovery — Web3 Protocol Identified a zero-click, unauthenticated IDOR vulnerability in a major L2 protocol's support infrastructure. Chained an unauthenticated wallet-to-userId lookup with an unprotected Server-Sent Events stream, enabling live surveillance of any user's private support tickets and KYC data with no authentication required. Two-command curl PoC. Submitted to protocol security team directly. Confidential.
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started