T09 · Insecure Skill Coding Practices
- Location
scripts/buy_and_sign.ts:74- Finding
Blind Signing and Broadcasting of Untrusted Blockchain Transactions
- Content
View full analysis
{ const response = await fetch(`${BASE_URL}/buy`, { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify(params), }); if (!response.ok) { const error = await response.text(); throw new Error(`HTTP ${response.status}: ${error}`); } return response.json(); } async function signAndSendTransaction( serializedTx: string, privateKey: string, rpcUrl: string = clusterApiUrl("mainnet-beta") ): Promise<{ success: boolean; signature?: string; explorerUrl?: string; error?: string }> { let keypair: Keypair; try { const keyBytes = bs58.decode(privateKey); keypair = Keypair.fromSecretKey(keyBytes); } catch (e) { return { success: false, error: `Invalid private key: ${e}` }; } let transaction: VersionedTransaction; try { const txBytes = bs58.decode(serializedTx); transaction = VersionedTransaction.deserialize(txBytes); } catch (e) { return { success: false, error: `Invalid transaction: ${e}` }; } try { transaction.sign([keypair]); } catch (e) { return { success: false, error: `Failed to sign: ${e}` }; ...[truncated 4650 chars]- Remediation
View remediation
