Skip to main content
ArcBlock Community

DID Wallet Automatically Enables TouchID Without Password

JM “cryptotestnet” Morales
Support
did-walletbugneed-reviewsecurityux

  1. Description The DID Wallet app enables TouchID for authentication without requiring the user to first enter their password. This bypasses the standard security flow, creating a risk of unauthorized access if the device is stolen or shared.
  2. Steps to Reproduce Open the DID Wallet app. Attempt to access a secured feature Instead of being prompted for a password, the app automatically enables TouchID for authentication. Observe that no password input is required to proceed.
  3. Expected Behavior Users should first enter their password to unlock the wallet. TouchID should only be enabled after successful password authentication (as a convenience option).
  4. Actual Behavior TouchID is enabled without password verification, allowing access to sensitive data or transactions.
  5. Severity Priority: Critical (Security/Authentication Bypass)
Reply