All reports
mediumBridge exploitEVM-Solidity

Malda: Unenforced maxFee and ttl Parameters in sendMsg Function

Payout
$0
Protocol
Malda
Disclosed
Aug 14, 2025
Source
sherlock

Malda's EverclearBridge.sendMsg forwards decoded cross-chain intent parameters to everclearFeeAdapter.newIntent without enforcing that maxFee and ttl are both zero, which the Everclear netting pathway requires. A rebalancer (the privileged caller) can therefor …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.