-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Labels
bugSomething isn't workingSomething isn't working
Description
Project version
0.3.1
What happened?
While creating the option, user is able to send reissuance tokens to himself(not the valid covenant). Therefore there is a possible attack on the buyers of the issuance tokens if they are not checking the blockchain.
Minimal reproduction steps
To recreate attack the creator could mint issuance tokens. Then sell the issuance tokens to somebody. In the end close the option with cancellation path and left buyers without their tokens.
In order to fix it, the option funder(or seller of the issuance tokens) should provide the creation transaction, so the buyer could verify that reissuance tokens are sent to the trusted covenant rather than the option creator himself.
KyrylR and apoelstra
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working