Security researchers disclose Dragonblood, a group of vulnerabilities impacting WiFi Alliance's recently launched WPA3 WiFi security and authentication standard
Dragonblood vulnerability discovered by the same security researcher who discovered the KRACK attack on WPA2.
Context & Ripple Effects
WPA3 was the WiFi Alliance's answer to KRACK, the 2017 flaw that let attackers eavesdrop on and hijack WPA2 traffic and drew a US CERT advisory. Now the researcher behind KRACK has turned the same lens on the successor standard itself, disclosing Dragonblood barely into WPA3's rollout.
The disclosure matters because it targets the standard at its design level rather than any single implementation — and because related coverage shows the pattern repeating: two years later, Frag Attacks would surface flaws reaching back across decades of Wi-Fi devices. A companion piece on KRACK argued IEEE's hard-to-access specs and separately vetted protocols let handshake flaws slip past scrutiny.
First-order effects
- Vendors shipping WPA3-certified routers and devices must issue patches, and the WiFi Alliance faces pressure to fix the standard's specification rather than leave fixes to individual implementers.
- Early adopters who migrated from WPA2 specifically to escape KRACK-class attacks find their new protection weakened at launch, complicating upgrade decisions for network operators.
Second-order effects
- Enterprises weighing a WPA3 migration are likely to stay on patched WPA2 longer, slowing the Alliance's transition timeline and extending the installed base of legacy protocol.
- The disclosure hands security auditors a template: the same designer-side analysis that found KRACK can be rerun against any new handshake, raising the bar for what counts as 'vetted' before a standard ships.
Third-order effects
- With KRACK, Dragonblood, and later Frag Attacks all breaking protocol generations at the handshake or framing layer, Wi-Fi security looks structurally prone to recurring design-level flaws — pointing toward open, widely reviewed specifications and formal verification of handshakes as prerequisites for future standards.
- If each generation keeps launching with exploitable designs, certification alone stops signaling safety, shifting trust toward rapid coordinated disclosure and patch cadence as the real security guarantee.
The trend: Wi-Fi security standards are being broken at the protocol-design layer faster than new generations ship, making continuous researcher scrutiny — not certification — the de facto quality gate.