CandleFocus

Wabisabi Deanonymization Vulnerability "Disclosed"

The GingerWallet, a fork of WasabiWallet, has received a vulnerability report that could potentially compromise the privacy of users participating in a coinjoin round. The vulnerability, discovered by developer drkgry, allows a malicious coordinator to deanonymize user inputs and outputs by performing an active attack. This vulnerability stems from the design of the Wasabi 2.0 coinjoin coordination, specifically the use of unique identifiers for users that can be exploited by a malicious coordinator. The issue was known by the team during the design phase of the Wabisabi protocol but was never fully addressed. The current implementation of Wasabi 2.0 has other outstanding vulnerabilities due to shortcuts taken during the implementation phase.

Related News