mediumSignature replayEVM-Solidity
Crestal Network: Signature Replay attack possible on `updateWorkerDeploymentConfigWithSig()` in Blueprintcore.sol which leads to users lose the funds
- Payout
- $0
- Protocol
- Crestal Network
- Disclosed
- Mar 14, 2025
- Source
- sherlock
Crestal Network's BlueprintCore.sol exposes updateWorkerDeploymentConfigWithSig(), which verifies a signer against a digest built by getRequestDeploymentDigest. Because that digest omits any per-user nonce, timestamp, or chain ID, a validly signed configuratio …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.