WhisperX tag archive

#blockchain_security

This page collects WhisperX intelligence signals tagged #blockchain_security. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-03-31 15:27:23 · GitHub Issues

1. Soroban SDK Security Flaw: Malicious RPC Can Reorder Contract Call Arguments via Fetched ABI

A critical security vulnerability has been identified in the Soroban SDK's contract client, where the system implicitly trusts the Application Binary Interface (ABI) fetched from a remote RPC endpoint. The flaw resides in the `Client.from()` and `Client.fromWasmHash()` methods, which retrieve WASM code from a configure...