highBridge exploitEVM-Solidity
Chakra: Invalid token address used in `ChakraSettlementHandler::cross_chain_erc20_settlement(...)` leading to invalid transaction creation and event emission
- Payout
- $0
- Protocol
- Chakra
- Disclosed
- Feb 20, 2025
- Source
- code4rena
In Chakra's Solidity settlement handler, the cross_chain_erc20_settlement function records the handler's own contract address (address(this)) as the from_token field both when storing the CreatedCrossChainTx record and when emitting the CrossChainLocked event, …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-08-chakra-findings/issues/380
- https://github.com/code-423n4/2024-08-chakra-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.