All reports
highLogic errorCosmos-SDK

SEDA Protocol: Anyone can pass any length to some Tally imports to inflate memory, induce OOM, and crash validators

Payout
$0
Protocol
SEDA Protocol
Disclosed
Mar 10, 2025
Source
sherlock

SEDA's WASM Tally runtime exposed imports such as secp256k1_verify whose message, signature, and public-key length parameters were unbounded. A malicious Tally program passing maximum unsigned values for all three lengths forced each validator to allocate roug …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.