All reports
mediumReentrancyEVM-Solidity

Centrifuge Protocol V3.1: Malicious adapters can exploit message batching via adapter-side reentrancy to cause message loss for any other pool

Payout
$0
Protocol
Centrifuge Protocol V3.1
Disclosed
Nov 17, 2025
Source
sherlock

Centrifuge's Gateway._endBatching() snapshots its batch locators into memory, immediately clears the transient storage array, and then loops over that stale in-memory snapshot to dispatch each batch through external adapter calls. Because isBatching remains tr …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.