Skip to content

Threefold account recovery allows mismatched name and Seed phrase #945

@atefnazmy

Description

@atefnazmy

Is there an existing issue for this?

  • I have searched the existing issues

What happened?

  • I have identified an issue where account recovery is possible using a seed phrase with a name that is not associated with the account

Steps To Reproduce

  • Create an account with a specific name (e.g., atef0) and a seed phrase.
  • Log out of the account.
  • Attempt to recover the account using the same seed phrase but with a different name (e.g., at).
  • Observe that the recovery is successful, even though the name does not match the original account.

Relevant screenshots/screen records

acc.mp4

Relevant log output

n/a

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

Status
Done

Relationships

None yet

Development

No branches or pull requests

Issue actions