Why Nostr? What is Njump?
2024-09-12 21:34:31

CryptoAudit on Nostr: If you have worked with Solidity, you are familiar with the ecrecover function. If ...

If you have worked with Solidity, you are familiar with the ecrecover function. If signature is not valid, this function returns signing address or 0. Therefore, the output of this function should always be checked.

You can easily write a rule for this pattern with the @semgrep tool and find all the cases that are not like this.
Author Public Key
npub1mtmlfn9c7sff6zfutdedj3prmrlhdwy5mne83xf34f3v7s57jknqs6mdys