All reports
highFront-running / MEVEVM-Solidity

Chakra: Malicious actors can manipulate the `cross_chain_callback` callback

Payout
$0
Protocol
Chakra
Disclosed
Feb 20, 2025
Source
code4rena

Chakra's cross-chain settlement contract signed the final callback message hash without the `from_chain` field, even though that field is used downstream to authorize the receiving handler. An attacker who observes a legitimate validator callback in the mempoo …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.