mediumReentrancyEVM-Solidity
Centrifuge Protocol V3.1: Malicious adapters can exploit message batching via adapter-side reentrancy to cause message loss for any other pool
- Payout
- $0
- Protocol
- Centrifuge Protocol V3.1
- Disclosed
- Nov 17, 2025
- Source
- sherlock
Centrifuge's Gateway._endBatching() snapshots its batch locators into memory, immediately clears the transient storage array, and then loops over that stale in-memory snapshot to dispatch each batch through external adapter calls. Because isBatching remains tr …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.