mediumLogic errorEVM-Solidity
Centrifuge Protocol V3.1: `MessageProcessor` fails to disable `unpaidMode` during `UntrustedContractUpdate` execution enabling permanent DOS via malicious unpayable batch creation
- Payout
- $0
- Protocol
- Centrifuge Protocol V3.1
- Disclosed
- Nov 17, 2025
- Source
- sherlock
Centrifuge V3.1's MessageProcessor leaves the Gateway in unpaidMode while executing UntrustedContractUpdate messages, so malicious contract code runs with the gateway configured to store underfunded outbound batches as unpaid rather than reverting. By submitti …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.