▐ homomorph ▌

rules / HM007

HM007 missing-sender-allowed HIGH

Caller-supplied ciphertext handle used without FHE.isSenderAllowed

Why it matters

A public function that accepts an already-encrypted handle (`euint64`, `ebool`, ...) directly from the caller must confirm the caller is actually allowed to use it. Handles are just 32-byte identifiers; without `FHE.isSenderAllowed(handle)` an attacker can pass any handle they observed on-chain, including another user's balance, and have the contract compute with or move it. This is the FHE equivalent of spending someone else's funds by guessing their account number.

Fix

At the top of the function: `require(FHE.isSenderAllowed(handle), "not allowed");`. Prefer accepting `externalEuintX` plus an input proof for fresh user inputs.

Check locally

homomorph scan . --rules HM007