mediumBridge exploitEVM-Solidity
Centrifuge Protocol V3.1: `Gateway.withBatch()` lacks message count validation enabling permanent DOS via an excessive number of messages in a batch
- Payout
- $0
- Protocol
- Centrifuge Protocol V3.1
- Disclosed
- Nov 17, 2025
- Source
- sherlock
Centrifuge's cross-chain Gateway allows anyone to call withBatch() and collect an unbounded number of messages into a single outbound batch, with no validation on message count. An attacker can bundle hundreds of cheap UntrustedContractUpdate messages together …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.