Worldcoin releases audit reports showing resolved security issues

29 July 2023

Cointelegraph By Tom Blackstone

The proof of humanity protocol released security audit reports claiming that most issues were fixed or mitigated.

News

Join us on social networks

Proof of humanity protocol Worldcoin released its audit reports on July 28 as criticism of its data collection practices continues to mount. The new reports were conducted by security consulting firms Nethermind and Least Authority.

According to an accompanying announcement from Worldcoin, Nethermind found 26 security issues with the protocol, of which 24 were “identified as fixed” during the verification phase, while one was mitigated and another was acknowledged.

Least Authority discovered three issues and made six suggestions, all of which “have been resolved or have planned resolutions,” the announcement stated.

Learn more about the results of two separate security audits of the Worldcoin protocol, performed by @NethermindEth & @LeastAuthority.https://t.co/fXa50wNBYE

— Worldcoin (@worldcoin)

July 28, 2023

Worldcoin first rose to prominence in 2021 when it announced that it would give away free tokens to any users who verify their humanity by having their iris scanned by a device called an “Orb.” The project was co-founded by Sam Altman, the co-founder of AI developer OpenAI.

At the time, Altman and other team members argued that AI bots would become an increasing problem on the internet if people didn’t find a way to verify their humanness without giving up their privacy. According to the protocol’s documentation, The Orb produces a hash of the user’s iris scan but does not keep a copy of the iris scan.

Related: Worldcoin confirms it is the cause of mysterious Safe deployments

Nethermind’s Worldcoin audit report. Source: GitHub

Worldcoin initiated its public launch on July 25 after nearly two years of development and beta testing. But criticism of it erupted almost immediately. The United Kingdom’s Information Commissioner’s Office (ICO) reportedly said the government body was deciding whether to investigate the project for violating the country’s data protection laws. French data protection agency — the National Commission on Informatics and Liberty — also questioned Worldcoin’s legality.

The crypto community was divided over the project’s launch, with some participants seeing it as the start of a dystopian future where privacy would be eliminated. In contrast, others saw it as a necessary step toward protecting humans against malicious artificial intelligence.

The new audit reports cover various security topics, including resistance to distributed denial of service attacks, case-specific implementation errors, key storage and proper management of encryption and signing of keys, data leaking and information integrity, and others. Some issues found resulted from dependencies on Semaphore and Ethereum, including “elliptic curve precompile support or Poseidon hash function configuration,” the announcement stated.

All issues except one were fixed, mitigated or have planned fixes. The one security issue that was not fixed by the time of verification has a severity of “undetermined” and is listed as “acknowledged.”

  

You might also like

SEC hacker counters prosecutors with 366-day sentencing recommendation  
SEC hacker counters prosecutors with 366-day sentencing recommendation  

Defense lawyers have asked a judge to sentence the person responsible for helping post a fake message announcing regulatory approval of Bitcoin exchange-traded funds to roughly a year in prison, countering prosecutors’ request for a two-year sentence.In a May 13 filing in the US District Court for the District of Columbia, Eric Council Jr.’s legal team asked that he be sentenced to no more than one year and one day in prison following his guilty plea. Council was part of a group that took control of the US Securities and Exchange Commission’s (SEC’s) X account in 2024 through a SIM swap attack, posting a message that suggested the regulator had approved spot Bitcoin (BTC) exchange-traded fund listings for the first time.“A sentence of twelve months and one day serves the ends of justice,” said the May 13 filing. “It sufficiently punishes the defendant for his role in this case. It also promotes respect for the law and deters future criminal conduct.”Eric Council Jr.’s sentencing recommendation, filed on May 13. Source: PACERCouncil initially pleaded not guilty to the charges, but changed his plea to guilty in February on one count of conspiracy to commit aggravated identity theft and access device fraud. The judge overseeing the case, Amy Berman Jackson, also ordered prosecutors to “identify the felony and point to where that information can be found in the record” by May 13.Prison sentence between 1 and 2 years?The SEC hacker is scheduled to be sentenced on May 16. Prosecutors asked the judge to impose a two-year sentence on Council, saying he “profited through a sophisticated fraud scheme.” Court filings showed he earned roughly $50,000 through similar SIM swap attacks.Related: ZKsync X hacker posts false SEC probe in apparent effort to crash tokenThough Council’s case was likely winding down with his upcoming sentencing hearing, the DC court district could soon be under new leadership, potentially affecting the prosecution of crypto-related cases. On May 8, US President Donald Trump announced that Fox News host Jeanine Pirro would become the interim US attorney for the District of Columbia.Magazine: SEC’s U-turn on crypto leaves key questions unanswered

South Korea’s Democratic Party sets up ‘Digital Asset Committee’  
South Korea’s Democratic Party sets up ‘Digital Asset Committee’  

The largest political party in South Korea, the Democratic Party, has launched a Digital Asset Committee focused on developing cryptocurrency policies and promoting industry growth.The committee held its inaugural meeting at the National Assembly Members’ Hall in Seoul on May 13, the local news agency News1 reported.During its first meeting, the committee highlighted the importance of resolving regulatory uncertainty and addressing burning issues like stablecoin regulation amid the push for US-dollar stablecoins by the US government.The new committee joins similar organizations in South Korea, including the Virtual Asset Committee launched in late 2024 and another public-private crypto task force introduced in 2022, both initiated by the Financial Services Commission (FSC).Exchanges like Upbit and Bithumb involvedThe leadership of the Digital Asset Committee includes South Korean officials and politicians, such as National Assembly Chairman Min Byeong-deok, who joined the committee as chairman.Additionally, the organization features standing general election committee Chairman Yoon Yeo-joon, Muksanism Committee Chairman Maeng Seong-gyu, National Assembly member Kim Byeong-gi and former National Assembly Chairman Kim Jeong-woo.Digital Asset Committee Chairman Min Byeong-deok, Yoon Yeo-jun, Maeng Seong-gyu and Kim Jeong-woo (from left to right). Source: News1According to a report by ChosunBiz, the committee will also include participation of executives from major local exchanges, including Upbit, Bithumb, Coinbit and Gopax.Criticism of “one-exchange, one bank” ruleAt the opening meeting, committee Chairman Min expressed concerns regarding limitations of South Korea’s current one-exchange-one-bank rule, implying that crypto exchanges are restricted to collaborating with only one lender.“There are clear shortcomings to the one exchange, one bank principle,” Min reportedly said, adding that the committee is working with regulators to resolve the issue.The chairman also mentioned discussions about which regulators should supervise the stablecoin industry and whether stablecoins should be subject to a licensing or reporting system.Related: South Korea presidential front-runner pledges to approve Bitcoin ETFs“There is also a point of contention as to whether the Bank of Korea or the FSC should handle the regulation,” he reportedly said.The news came shortly after a Bank of Korea executive expressed concerns over the issuance of the South Korean won-backed stablecoins.“Stablecoin has a great impact on the implementation of central bank policies such as monetary policy, financial stability, and payment settlement,” Bank of Korea’s Koh Kyung-chul reportedly said at a conference on May 12.“The negative impact on the central bank’s policy implementation should be minimized by the central bank’s practical intervention in the approval stage,” he added.Magazine: Finally blast into space with Justin Sun, Vietnam’s new national blockchain: Asia Express

Arizona governor kills two crypto bills, cracks down on Bitcoin ATMs  
Arizona governor kills two crypto bills, cracks down on Bitcoin ATMs  

Arizona Governor Katie Hobbs vetoed two key cryptocurrency-related bills that aimed to expand the state’s involvement in digital assets while signing a strict regulatory measure targeting Bitcoin ATMs.On May 12, Hobbs rejected Senate Bill 1373, which sought to establish a Digital Assets Strategic Reserve Fund. The fund would have allowed Arizona to hold crypto assets obtained through seizures or legislative allocations.“Current volatility in cryptocurrency markets does not make a prudent fit for general fund dollars,” she stated in her veto letter. “I have already signed legislation this session which allows the state to utilize cryptocurrency without placing general fund dollars at risk,” she added.That decision followed her veto of Senate Bill 1025 — the more ambitious “Arizona Strategic Bitcoin Reserve Act” — on May 3. It would have authorized up to 10% of the state’s treasury and retirement funds to be invested in Bitcoin and other digital assets.According to data from bitcoinlaws.io, 26 US states have introduced strategic crypto reserve bills, with 18 of them currently active. Hobbs also vetoed Senate Bill 1024, which would have permitted state agencies to accept cryptocurrency payments for taxes, fines and fees via approved service providers.Although the proposal attempted to shield the state from direct exposure to price volatility, Hobbs said it still introduced “too much risk.”Source: State of Arizona, Office of the GovernorRelated: Taiwan lawmaker calls for Bitcoin reserve at national conferenceHobbs approves Bitcoin ATM billOn May 12, Hobbs approved House Bill 2387, which introduces new consumer protection rules for cryptocurrency kiosk (ATM) operators, aiming to reduce fraud and improve transparency.The bill mandates that kiosks display clear, multilingual warnings about common crypto scams and require users to acknowledge these risks before completing transactions. Operators must also provide detailed receipts that include transaction data, contact information, fees and refund policies.Furthermore, the bill caps transactions at $2,000 per day for new customers and $10,500 per day for returning users after 10 days. Kiosk providers must also offer 24/7 toll-free customer service and post the number visibly on each machine.Under the bill, if a new user is tricked into sending crypto under false pretenses and reports it with proof within 30 days, they are entitled to a full refund, including fees.According to CoinATMRadar, there are currently 20 active Bitcoin ATMs in Arizona. Notably, Hobbs has not entirely closed the door on digital assets. On Wednesday, she signed House Bill 2749, which updates Arizona’s unclaimed property laws to include digital assets.The legislation allows the state to retain unclaimed cryptocurrencies in their original form rather than liquidating them into fiat currency.Magazine: Bitcoin eyes ‘crazy numbers,’ JD Vance set for Bitcoin talk: Hodler’s Digest, May 4 – 10

Open chat
1
BlockFo Chat
Hello 👋, How can we help you?
📱 When you've pressed the BlockFo button, we automatically transfer to WhatsApp 🔝🔐
🖥️ Or, if you use a PC or Mac, then we'll open a new window to load your desktop app.