logo

How a Race Condition Vulnerability Could Cast Multiple Votes

ID: 3d1e982f-f158-57a3-a29e-bb46a3ab13b0

STIX ID: report--3d1e982f-f158-57a3-a29e-bb46a3ab13b0

Feed Name: HackerOne Blog

Threat Score
45/100

Date Published: 2024-11-26

Date Updated: 2026-06-12

...
...

This report describes discovery of a race condition in the Worldcoin (World ID) SDK cloud implementation that allowed an attacker to bypass preset per-person verification limits by sending parallel requests, enabling actions such as casting multiple votes. The author details testing steps, the vulnerable code path, and the subsequent database-backed mitigation that prevents concurrent verification misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.