PT-2022-23372 · Chia Network · Chia Network Cat1 Standard

Published

2022-07-29

·

Updated

2022-08-10

·

CVE-2022-36447

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chia Network CAT1 Standard version 1.0.0
Description An inflation issue was discovered in the Chia Network CAT1 Standard, allowing previously minted tokens to be inflated to an arbitrary extent by any holder of any amount of the token. The total amount of the token can be increased as high as the malicious actor pleases, regardless of issuance rules. This issue affects every CAT1 on the Chia blockchain. The attack is auditable on-chain, so maliciously altered coins can potentially be marked by off-chain observers as malicious.
Recommendations For Chia Network CAT1 Standard version 1.0.0, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Related Identifiers

CVE-2022-36447
GHSA-PVJG-JWP3-MRJ5
PYSEC-2022-43072

Affected Products

Chia Network Cat1 Standard