▐ homomorph ▌

rules / HM006

HM006 unverified-cleartext CRITICAL

Decrypted cleartext accepted on-chain without FHE.checkSignatures

Why it matters

In the public-decryption flow, cleartexts are produced off-chain by the KMS and submitted back to the contract together with a signed proof. If the contract stores the submitted values without calling `FHE.checkSignatures(handles, abi.encode(values...), proof)`, anyone can submit fabricated results: fake auction winners, forged vote tallies, or an inflated balance reveal. The ciphertexts were never really decrypted; the attacker simply told the contract what to believe.

Fix

Reconstruct the exact handle list that was decrypted, then verify before trusting anything: `FHE.checkSignatures(handles, abi.encode(v1, v2), decryptionProof);`. For legacy `requestDecryption` callbacks, protect the callback with `onlyGateway` and verify signatures.

Check locally

homomorph scan . --rules HM006