civkit / civkit/staking-credentials-spec

Link `Credential` authentication request to proof of scarce asset ?

Open
#6 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

The current staking credential issuance flow sounds to suffer from the current vulnerability:
- an Issuer announce a destination pubkey Y to be paid on-chain
- a Requester wallet pay the destination pubkey with a Tx A
- the Tx A is observed on-chain and correlated with Issuer policy destination pubkey Y
- the Credentials are issued for the observer instead of the on-chain honest payer

The credentials asset proof could be linked to the on-chain transaction, e.g BIP322.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by reviewing the staking credential issuance flow and the proposed BIP322 transaction linkage; done would require an agreed authentication binding that prevents credentials being issued to an observer rather than the payer.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, blockchain, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.