HIGH SEVERITYCONFIRMED

ENS normalize_name() silently maps 62 fullwidth Unicode chars to ASCII — phishing vector

Package
web3
Version
7.14.1
Verified
2026-03-28

Description

web3.py's `ens.utils.normalize_name()` silently folds all 62 fullwidth alphanumeric characters (U+FF10–U+FF5A) to their ASCII equivalents during ENSIP-15 normalization. `normalize_name('vit\uff41lik.eth')` returns `'vitalik.eth'` — identical to the real name. An attacker can register a fullwidth-character ENS name that resolves to their own address while displaying identically to a trusted name after normalization, enabling ETH address hijacking.

Reproduction

from ens.utils import normalize_name
normalize_name('vit\uff41lik.eth')  # fullwidth a (U+FF41)
# Returns: 'vitalik.eth'  — SAME as the real name
normalize_name('vitalik.eth')
# Returns: 'vitalik.eth'  — indistinguishable after normalization
← All bugsScan your code →