Will a significant security flaw be discovered in the WorldCoin Protocol before 2024?
26
125
510
resolved Oct 19
Resolved
YES

This market resolves YES if a significant security flaw is published and confirmed by security experts before 2024. If a qualifying flaw is discovered and is then swiftly and successfully patched such that the vulnerability is extinguished entirely in short order, this market still resolves YES.

A "significant" security flaw is any flaw that allows a user to bypass or significantly degrade the security guarantees made by the WorldCoin protocol. This is somewhat subjective and I will reserve the right to make the final judgment, but qualifying incidents include, but are not limited to:

  1. A bot is able to reliably pose as a human (especially if this can be scaled to large numbers)

  2. A user is able to reliably impersonate another user

  3. A user is able to appropriate funds or tokens from other users in a manner not intended by the protocol

If January 1, 2024 rolls around and no significant security flaw has been published and confirmed by security experts yet, this market resolves NO.

Get Ṁ200 play money

🏅 Top traders

#NameTotal profit
1Ṁ265
2Ṁ139
3Ṁ104
4Ṁ103
5Ṁ36
Sort by:
predicted YES

@RobertCousineau This would indeed be a valid claim if verified. Do we have a public confirmation by WorldCoin or by a trustworthy third party?

@LarsDoucet Okay they’re on record:

“On May 29, CertiK’s Security Team reported a bug to Worldcoin that could allow an attacker to create an inactive Operator account," a Worldcoin spokesperson told Decrypt. "The bug did not allow anyone to bypass the manual review for establishing an Operator account and at no point was access to Orbs or data enabled through the bug. The Worldcoin security team acknowledged and fixed the issue within 24 hours of receipt of information from CertiK and verified that it has not been abused."

This resolves YES

bought Ṁ53,907 of YES

@LarsDoucet WorldCoin is downplaying the significance, and it’s already been patched, but being able to bypass the basic verification process seems like a big deal to me. Meets the literal terms of this market. Might make a second market to more explicitly capture “and then something really bad actually happens”

bought Ṁ20 of YES

Does fraud or rug pull or exit scam also count as a vulnerability?

predicted YES

does this include the case where a user fraudulently signs up twice (for instance, because the orb doesn't recognize the duplicate?) if so, does that have to happen in large numbers or does one incident count? does it matter whether it can be replicated intentionally, as opposed to the scanning software just failing sometimes but without a good way to systematically exploit it?

seems to maybe fall under "a user is able to appropriate funds or tokens from other users in a manner not intended by the protocol", but indirectly, in the sense that double-dipping from an airdrop deflates the currency a little or takes from the total pool that might be available.

I'm torn between being certain they've fucked up somewhere and fairly sure that nobody is going to care enough about the coin to find anything but the most glaring errors.