logo

Fortifying ZenGo: Unearthing and Defending Against Privileged User Attacks

ID: 5ea87e58-686f-5c96-9bfd-b5f202ce9c7b

STIX ID: report--5ea87e58-686f-5c96-9bfd-b5f202ce9c7b

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2023-04-04

Date Updated: 2026-06-11

...
...

CertiK's SkyFall team evaluated ZenGo's MPC wallet design and found a misimplementation in the device key enrollment API that allowed a privileged attacker who can extract the client's Master Key 2 and API token to register a new device key and perform transactions (the "Device Fork Attack"); ZenGo implemented server-side biometric enforcement to mitigate the issue and CertiK confirmed the patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.