jwt-authentication

1 article
sort: new top best
clear filter
0 7/10
vulnerability

A critical authorization bypass vulnerability in BitSwift's dApp frontend allowed unauthenticated users to mint unlimited BCAD tokens via an unprotected /bcad/credit endpoint that lacked proper admin permission checks, enabling attackers to drain liquidity pools. The researcher earned a $4,515 bounty after responsibly disclosing the issue.

BitSwift Bitswift Cash BCAD token Immunefi JWT BigNumber
medium.com · unknown · 22 hours ago · details