All reports
mediumLogic errorEVM-Solidity

zkSync: EIP-155 is not enforced, allowing attackers/malicious operators to profit from replaying transactions

Payout
$0
Protocol
zkSync
Disclosed
Feb 29, 2024
Source
code4rena

zkSync Era's transaction validation in DefaultAccount.validateTransaction and the bootloader encoding omit the chain ID from the signed payload of legacy transactions whenever reserved[0] is zero, which happens automatically for legacy txs carrying a signature …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.