All reports
highAccess controlMove

Maia DAO Ecosystem: An attacker can mint an arbitrary amount of `hToken` on `RootChain`

Payout
$0
Protocol
Maia DAO Ecosystem
Disclosed
Sep 18, 2023
Source
code4rena

A vulnerability in `BranchBridgeAgent.callOutSignedAndBridgeMultiple` allows an attacker to manipulate cross-chain deposit payloads sent to the `RootChain`. An unsafe cast of the token array length to `uint8` overflows when more than 256 items are supplied, ca …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.