{"id":44844,"date":"2023-08-05T11:30:36","date_gmt":"2023-08-05T15:30:36","guid":{"rendered":"https:\/\/ifintechworld.com\/markets\/crypto\/blockchain-security-firm-certik-reveals-vulnerability-in-worldcoin-protocol-allowing-unverified-orb-operator-access\/"},"modified":"2023-08-05T11:30:38","modified_gmt":"2023-08-05T15:30:38","slug":"blockchain-security-firm-certik-reveals-vulnerability-in-worldcoin-protocol-allowing-unverified-orb-operator-access","status":"publish","type":"post","link":"https:\/\/ifintechworld.com\/?p=44844","title":{"rendered":"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access"},"content":{"rendered":"<div>\n<p>Blockchain security firm\u00a0<strong>CertiK\u00a0<\/strong>has disclosed a vulnerability in the\u00a0<strong>Worldcoin\u00a0<\/strong>protocol that allowed unauthorized access for an Orb operator.\u00a0<\/p>\n<p>In a recent Twitter thread, CertiK explained that the vulnerability allowed anyone to bypass the verification requirements to become an Orb operator without meeting the necessary criteria, such as being a legitimate company or passing a vetting interview.\u00a0<\/p>\n<p>&#8220;Through this security vulnerability, a malicious attacker could bypass the verification and strict participation criteria of the Worldcoin Operator acceptance process,&#8221; the company wrote.\u00a0<\/p>\n<p>The usual process allows only legitimate businesses that pass strict identification verification to run an Orb operation, which collects users&#8217; iris information.\u00a0<\/p>\n<figure class=\"media\"><oembed data-embedo-height=\"400\" data-embedo-url=\"https:\/\/twitter.com\/CertiK\/status\/1687129302414835712?s=20\" loading=\"lazy\"><\/oembed><\/figure>\n<p>CertiK said it reported the issue to Worldcoin through a whitehat disclosure procedure, and the project&#8217;s security team quickly addressed the vulnerability with a fix.<\/p>\n<p>&#8220;CertiK has since verified and confirmed that the fix mitigated the threat,&#8221; the company wrote.<\/p>\n<p>Notably, CertiK&#8217;s disclosure comes just a week after Worldcoin released a report on security audits conducted by Nethermind and Least Authority.\u00a0<\/p>\n<p>The audits covered various areas, including vulnerabilities in the code that could lead to adversarial actions and other attacks, as well as protection against malicious attacks and exploitation methods.<\/p>\n<p>Nethermind&#8217;s audit identified 26 items during the security assessment, of which 24 were fixed after the verification stage, one was mitigated, and one was acknowledged.<\/p>\n<p>On the other hand, Least Authority discovered three issues in the protocol and provided six suggestions, all of which have either been resolved or have planned resolutions, according to Worldcoin.<\/p>\n<h2>Worldcoin Faces More Issues Amid Kenya Suspension<\/h2>\n<p>Last week, Kenya\u2019s Ministry of the Interior\u00a0issued a decree\u00a0suspending Worldcoin signup, citing concerns about its activities\u2019 authenticity, legality, security, financial services, and data protection.\u00a0<\/p>\n<p>In an official announcement, the ministry said relevant agencies had begun investigating the project.<\/p>\n<p>\u201cRelevant security, financial services and data protection agencies have commenced inquiries and investigations to establish the authenticity and legality of the aforesaid activities,\u201d interior minister Kithure Kindiki said at the time.<\/p>\n<figure class=\"media\"><oembed data-embedo-height=\"400\" data-embedo-url=\"https:\/\/twitter.com\/MwangoCapital\/status\/1686632198072340481?s=20\" loading=\"lazy\"><\/oembed><\/figure>\n<p>Worldcoin, co-founded by OpenAI CEO Sam Altman and valued at over $2 billion, aims to create a \u201cproof-of-personhood\u201d network by\u00a0registering verified humans through eyeball scans.\u00a0<\/p>\n<p>The project has already received notable criticism since its debut.\u00a0<\/p>\n<p>Since Worldcoin scans people\u2019s irises and eyes to ensure that the crypto is distributed fairly, some have expressed privacy and security concerns.\u00a0<\/p>\n<p>The collection of biometric data has also raised questions about how this sensitive information will be stored, protected, and potentially used.<\/p>\n<p>Furthermore, some have questioned Worldcoin\u2019s methods of obtaining consent.\u00a0<\/p>\n<p>A 2022\u00a0investigation by MIT Review\u00a0found that Worldcoin used deceptive marketing practices, collected more personal data than disclosed, and failed to obtain meaningful informed consent.<\/p>\n<p>Just recently, it was revealed that\u00a0<strong>European\u00a0<\/strong>regulators, including the\u00a0<strong>French National Commission on Informatics and Liberty (CNIL)<\/strong>\u00a0and the\u00a0<strong>Bavarian state authority in Germany<\/strong>,\u00a0are collaborating\u00a0with an investigation into the project.\u00a0<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>Read the full article <a href=\"https:\/\/cryptonews.com\/news\/blockchain-security-firm-certik-reveals-vulnerability-worldcoin-protocol-allowing-unverified-orb-operator-access.htm\" target=\"_blank\" rel=\"noopener\">here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Blockchain security firm\u00a0CertiK\u00a0has disclosed a vulnerability in the\u00a0Worldcoin\u00a0protocol that allowed unauthorized access for an Orb operator.\u00a0 In a recent Twitter thread, CertiK explained that the vulnerability allowed anyone to bypass the verification requirements to become an Orb operator without meeting the necessary criteria, such as being a legitimate company or passing a vetting interview.\u00a0 &#8220;Through [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":44845,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243],"tags":[83],"class_list":["post-44844","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto","tag-featured"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access | iFintechWorld<\/title>\n<meta name=\"description\" content=\"Blockchain security firm\u00a0CertiK\u00a0has disclosed a vulnerability in the\u00a0Worldcoin\u00a0protocol that allowed unauthorized access for an Orb operator.\u00a0In a recent\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ifintechworld.com\/?p=44844\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access | iFintechWorld\" \/>\n<meta property=\"og:description\" content=\"Blockchain security firm\u00a0CertiK\u00a0has disclosed a vulnerability in the\u00a0Worldcoin\u00a0protocol that allowed unauthorized access for an Orb operator.\u00a0In a recent\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ifintechworld.com\/?p=44844\" \/>\n<meta property=\"og:site_name\" content=\"iFintechWorld\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-05T15:30:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-08-05T15:30:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/08\/crypto-worldcoin-orb-2303.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"News Room\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"News Room\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/ifintechworld.com\/?p=44844#article\",\"isPartOf\":{\"@id\":\"https:\/\/ifintechworld.com\/?p=44844\"},\"author\":{\"name\":\"News Room\",\"@id\":\"https:\/\/ifintechworld.com\/#\/schema\/person\/6224724fd4116361255b179dc5c70b61\"},\"headline\":\"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access\",\"datePublished\":\"2023-08-05T15:30:36+00:00\",\"dateModified\":\"2023-08-05T15:30:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/ifintechworld.com\/?p=44844\"},\"wordCount\":495,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/ifintechworld.com\/#organization\"},\"keywords\":[\"Featured\"],\"articleSection\":[\"Crypto\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/ifintechworld.com\/?p=44844#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/ifintechworld.com\/?p=44844\",\"url\":\"https:\/\/ifintechworld.com\/?p=44844\",\"name\":\"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access | iFintechWorld\",\"isPartOf\":{\"@id\":\"https:\/\/ifintechworld.com\/#website\"},\"datePublished\":\"2023-08-05T15:30:36+00:00\",\"dateModified\":\"2023-08-05T15:30:38+00:00\",\"description\":\"Blockchain security firm\u00a0CertiK\u00a0has disclosed a vulnerability in the\u00a0Worldcoin\u00a0protocol that allowed unauthorized access for an Orb operator.\u00a0In a recent\",\"breadcrumb\":{\"@id\":\"https:\/\/ifintechworld.com\/?p=44844#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/ifintechworld.com\/?p=44844\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/ifintechworld.com\/?p=44844#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ifintechworld.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ifintechworld.com\/#website\",\"url\":\"https:\/\/ifintechworld.com\/\",\"name\":\"Repay Down\",\"description\":\"Latest Personal Finance News, Tips and Updates\",\"publisher\":{\"@id\":\"https:\/\/ifintechworld.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ifintechworld.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/ifintechworld.com\/#organization\",\"name\":\"Repay Down\",\"url\":\"https:\/\/ifintechworld.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ifintechworld.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/rep-logo-dark.png\",\"contentUrl\":\"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/rep-logo-dark.png\",\"width\":558,\"height\":90,\"caption\":\"Repay Down\"},\"image\":{\"@id\":\"https:\/\/ifintechworld.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/ifintechworld.com\/#\/schema\/person\/6224724fd4116361255b179dc5c70b61\",\"name\":\"News Room\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ifintechworld.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/avatar_user_1_1682606986-96x96.png\",\"contentUrl\":\"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/avatar_user_1_1682606986-96x96.png\",\"caption\":\"News Room\"},\"sameAs\":[\"https:\/\/ifintechworld.com\"],\"url\":\"https:\/\/ifintechworld.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access | iFintechWorld","description":"Blockchain security firm\u00a0CertiK\u00a0has disclosed a vulnerability in the\u00a0Worldcoin\u00a0protocol that allowed unauthorized access for an Orb operator.\u00a0In a recent","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ifintechworld.com\/?p=44844","og_locale":"en_US","og_type":"article","og_title":"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access | iFintechWorld","og_description":"Blockchain security firm\u00a0CertiK\u00a0has disclosed a vulnerability in the\u00a0Worldcoin\u00a0protocol that allowed unauthorized access for an Orb operator.\u00a0In a recent","og_url":"https:\/\/ifintechworld.com\/?p=44844","og_site_name":"iFintechWorld","article_published_time":"2023-08-05T15:30:36+00:00","article_modified_time":"2023-08-05T15:30:38+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/08\/crypto-worldcoin-orb-2303.jpg","type":"image\/jpeg"}],"author":"News Room","twitter_card":"summary_large_image","twitter_misc":{"Written by":"News Room","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/ifintechworld.com\/?p=44844#article","isPartOf":{"@id":"https:\/\/ifintechworld.com\/?p=44844"},"author":{"name":"News Room","@id":"https:\/\/ifintechworld.com\/#\/schema\/person\/6224724fd4116361255b179dc5c70b61"},"headline":"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access","datePublished":"2023-08-05T15:30:36+00:00","dateModified":"2023-08-05T15:30:38+00:00","mainEntityOfPage":{"@id":"https:\/\/ifintechworld.com\/?p=44844"},"wordCount":495,"commentCount":0,"publisher":{"@id":"https:\/\/ifintechworld.com\/#organization"},"keywords":["Featured"],"articleSection":["Crypto"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/ifintechworld.com\/?p=44844#respond"]}]},{"@type":"WebPage","@id":"https:\/\/ifintechworld.com\/?p=44844","url":"https:\/\/ifintechworld.com\/?p=44844","name":"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access | iFintechWorld","isPartOf":{"@id":"https:\/\/ifintechworld.com\/#website"},"datePublished":"2023-08-05T15:30:36+00:00","dateModified":"2023-08-05T15:30:38+00:00","description":"Blockchain security firm\u00a0CertiK\u00a0has disclosed a vulnerability in the\u00a0Worldcoin\u00a0protocol that allowed unauthorized access for an Orb operator.\u00a0In a recent","breadcrumb":{"@id":"https:\/\/ifintechworld.com\/?p=44844#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ifintechworld.com\/?p=44844"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/ifintechworld.com\/?p=44844#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ifintechworld.com\/"},{"@type":"ListItem","position":2,"name":"Blockchain Security Firm CertiK Reveals Vulnerability in Worldcoin Protocol Allowing Unverified Orb Operator Access"}]},{"@type":"WebSite","@id":"https:\/\/ifintechworld.com\/#website","url":"https:\/\/ifintechworld.com\/","name":"Repay Down","description":"Latest Personal Finance News, Tips and Updates","publisher":{"@id":"https:\/\/ifintechworld.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ifintechworld.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/ifintechworld.com\/#organization","name":"Repay Down","url":"https:\/\/ifintechworld.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ifintechworld.com\/#\/schema\/logo\/image\/","url":"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/rep-logo-dark.png","contentUrl":"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/rep-logo-dark.png","width":558,"height":90,"caption":"Repay Down"},"image":{"@id":"https:\/\/ifintechworld.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/ifintechworld.com\/#\/schema\/person\/6224724fd4116361255b179dc5c70b61","name":"News Room","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ifintechworld.com\/#\/schema\/person\/image\/","url":"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/avatar_user_1_1682606986-96x96.png","contentUrl":"https:\/\/ifintechworld.com\/wp-content\/uploads\/2023\/04\/avatar_user_1_1682606986-96x96.png","caption":"News Room"},"sameAs":["https:\/\/ifintechworld.com"],"url":"https:\/\/ifintechworld.com\/?author=1"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ifintechworld.com\/index.php?rest_route=\/wp\/v2\/posts\/44844","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ifintechworld.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ifintechworld.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ifintechworld.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ifintechworld.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=44844"}],"version-history":[{"count":1,"href":"https:\/\/ifintechworld.com\/index.php?rest_route=\/wp\/v2\/posts\/44844\/revisions"}],"predecessor-version":[{"id":44846,"href":"https:\/\/ifintechworld.com\/index.php?rest_route=\/wp\/v2\/posts\/44844\/revisions\/44846"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ifintechworld.com\/index.php?rest_route=\/wp\/v2\/media\/44845"}],"wp:attachment":[{"href":"https:\/\/ifintechworld.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=44844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ifintechworld.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=44844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ifintechworld.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=44844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}