HIGH SEVERITYCONFIRMED
ENS normalize_name() silently maps 62 fullwidth Unicode chars to ASCII — phishing vector
Package
web3
Version
7.14.1
Verified
2026-03-28
Description
web3.py's `ens.utils.normalize_name()` silently folds all 62 fullwidth alphanumeric characters (U+FF10–U+FF5A) to their ASCII equivalents during ENSIP-15 normalization. `normalize_name('vit\uff41lik.eth')` returns `'vitalik.eth'` — identical to the real name. An attacker can register a fullwidth-character ENS name that resolves to their own address while displaying identically to a trusted name after normalization, enabling ETH address hijacking.
Reproduction
from ens.utils import normalize_name
normalize_name('vit\uff41lik.eth') # fullwidth a (U+FF41)
# Returns: 'vitalik.eth' — SAME as the real name
normalize_name('vitalik.eth')
# Returns: 'vitalik.eth' — indistinguishable after normalization