rules / HM006
HM006 unverified-cleartext CRITICAL
Decrypted cleartext accepted on-chain without FHE.checkSignatures
Why it matters
In the public-decryption flow, cleartexts are produced off-chain by the KMS and submitted back to the contract together with a signed proof. If the contract stores the submitted values without calling `FHE.checkSignatures(handles, abi.encode(values...), proof)`, anyone can submit fabricated results: fake auction winners, forged vote tallies, or an inflated balance reveal. The ciphertexts were never really decrypted; the attacker simply told the contract what to believe.
Fix
Reconstruct the exact handle list that was decrypted, then verify before trusting anything: `FHE.checkSignatures(handles, abi.encode(v1, v2), decryptionProof);`. For legacy `requestDecryption` callbacks, protect the callback with `onlyGateway` and verify signatures.
Check locally
homomorph scan . --rules HM006