civkit / civkit/staking-credentials-spec
Link `Credential` authentication request to proof of scarce asset ?
- Dominant language
- No language data
- Stars
- 3
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
The current staking credential issuance flow sounds to suffer from the current vulnerability:
- an Issuer announce a destination pubkey Y to be paid on-chain
- a Requester wallet pay the destination pubkey with a Tx A
- the Tx A is observed on-chain and correlated with Issuer policy destination pubkey Y
- the Credentials are issued for the observer instead of the on-chain honest payer
The credentials asset proof could be linked to the on-chain transaction, e.g BIP322.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files, tests, or entry points. Start by reviewing the staking credential issuance flow and the proposed BIP322 transaction linkage; done would require an agreed authentication binding that prevents credentials being issued to an observer rather than the payer.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, blockchain, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100