logo

Uncovering and Resolving a Cross-Site Scripting Attack in a Popular Wallet Protocol

ID: c27b5252-9bff-572a-b9fe-cf7a76f2a7df

STIX ID: report--c27b5252-9bff-572a-b9fe-cf7a76f2a7df

Feed Name: CertiK Blog

Threat Score
50/100

Date Published: 2023-12-17

Date Updated: 2026-06-11

...
...

This report describes the discovery and responsible disclosure of a reflected XSS vulnerability in WalletConnect's Verify API that allowed attacker-controlled payloads to be embedded in a token returned in a JavaScript context, enabling phishing pages that could trick users into signing malicious transactions; WalletConnect patched the validation logic to whitelist allowed characters and the issue was fixed within days of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.