dymensionxyz/dymension

EIP155 keys owned by other rollapps can be overwritten

srene opened this issue · 0 comments

the ParseChainID function trims whitespace characters from the chain ID before checking whether the chain ID is EVM-compatible. This is problematic because malicious rollapp creators can overwrite the EIP155 key storage into their own rollapps using the same chain ID with extra whitespaces.