WhisperX tag archive

#whitelist

This page collects WhisperX intelligence signals tagged #whitelist. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-25 10:27:20 · GitHub Issues

1. Factory `create_pool` Allows Spoofing of `creator` Parameter, Risking Frontend Attribution

A security issue in the Factory contract allows an authorized user to spoof pool ownership, creating a risk of misattribution on the frontend dashboard. The `create_pool` function accepts an arbitrary address as the `creator` parameter, which is then broadcast in an event. This means the recorded creator is not necessa...

The Lab · 2026-03-28 11:26:58 · GitHub Issues

2. Security Alert: Factory `create_pool` Fails to Validate Token Against Whitelist, Risking Malicious Pools

A critical security vulnerability has been identified in the Factory contract's `create_pool` function. The function accepts an arbitrary `currency` identifier but fails to authenticate this token address against the official `DataKey::SupportedToken` configuration whitelist. This oversight allows unverified and potent...