A forgery attack on the Block.co blockchain-based digital credential certification system
This paper identifies a fundamental security flaw in blockchain-based certification systems, which undermines trust in decentralized credential verification for academic institutions and other users.
The authors demonstrate a vulnerability in the Block.co blockchain-based digital credential certification system that allows production of forged certificates recognized as valid by the system, and argue this attack is likely extendable to other systems using the same approach.
Certification of digital documents, such as academic credentials, seems a particularly suitable application for the use of blockchain and distributed ledger technologies. Indeed, these technologies enable decentralized certification systems that rely on the immutability and persistence of their distributed ledgers. However, in the absence of a central trusted authority, it is not easy to guarantee the authenticity of the connection between the real identity of an academic institution and the digital identity of the certificate issuer. In this paper, we demonstrate that one of such systems, known as Block.co, has a vulnerability that allows the production of forged certificates that are recognized as valid by the system. Since this is an inherent limitation of the approach used for blockchain-based certification, our attack is likely to be extendable to other systems adopting the same approach.