ensdomains / ens

Implementations for ENS core functionality: The registry, registrars, and public resolvers.

Home Page:https://ens.domains/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Report an ENS Zero Width Joiner vulnerability- This could lead to massive scams

0xyicheng opened this issue · comments

Problem Description

When you try to search, type: abc%E2%80%8C and you will see that abc.eth can be registered.
The domain owner is different from the real abc.eth owner
There are some such issues, including eth.eth, Vitalik.eth, etc.
Domain name +%E2%80%8C can register almost all duplicate domain names, the front end will not display the %E2%80%8C string
This may bring a lot of scams and misdirection, I hope this problem can be solved soon

Example

1

2

full question

#396