Executive brief
SLPJS is a JavaScript library for validating SLP (Simple Ledger Protocol) tokens, which are digital assets created on cryptocurrency networks. Versions before 0.27.4 incorrectly validate NFT1 child token creation, allowing attackers to create fake tokens without the required token burn. This could enable fraud, token counterfeiting, and loss of trust in the SLP token ecosystem.
Technical details
The vulnerability is a validation bypass (CWE-697: Incorrect Comparison) in SLPJS's NFT1 Child Genesis transaction validator. The library incorrectly accepts NFT1 child token creation transactions that do not burn the required NFT1 Group token, violating the NFT1 specification. The bug allows a wallet implementation or attacker with network access to broadcast and validate fraudulent tokens. No authentication is required; the attack succeeds at the protocol validation layer. The vulnerability was fixed in version 0.27.4 with improved validation logic.
Affected products
- SimpleLD SLPJS < 0.27.4
Timeline
- 2020-07-30: disclosed
- 2020-07-30: patched: Version 0.27.4 released