highLogic errorCosmos-SDK
SEDA Protocol: Anyone can pass any length to some Tally imports to inflate memory, induce OOM, and crash validators
- Payout
- $0
- Protocol
- SEDA Protocol
- Disclosed
- Mar 10, 2025
- Source
- sherlock
SEDA's WASM Tally runtime exposed imports such as secp256k1_verify whose message, signature, and public-key length parameters were unbounded. A malicious Tally program passing maximum unsigned values for all three lengths forced each validator to allocate roug …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.