The controversial Worldcoin project had a serious security vulnerability, CertiK has disclosed on X (formerly known as Twitter). Worldcoin pays people to become part of its World ID ecosystem by submitting scans of their irises through a device Worldcoin calls an Orb.
According to security platform CertiK, the vulnerability in the vetting process for operators could have allowed an attacker to bypass the verification process and operate an Orb without being interviewed or having a proper ID. “It would not need to be a company,” according to the post.
1/ On May 29th, CertiK reported a security vulnerability to #WorldCoin’s security team that could potentially allow an attacker to become an Orb operator by bypassing the verification process.
— CertiK (@CertiK) August 3, 2023
CertiK reported the vulnerability to the Worldcoin (WLD) security team as a “standard whitehat disclosure,” and it has been fixed, it said. The discovery of the vulnerability could add fuel to the worldwide controversy surrounding the project’s privacy and data use.
Related: Users said CertiK’s warning was a false alarm — then the project rugged
Critics have already suggested that the project, launched by OpenAI founder Sam Altman and intended to support its World App wallet by filtering out bots, is ethically questionable and contains the makings of a…