mediumBridge exploitEVM-Solidity
Most Aleph Zero Bridge: Inconsistency in Handling WETH in `eth::most::receiveRequest`
- Payout
- $0
- Protocol
- Most Aleph Zero Bridge
- Disclosed
- Mar 21, 2024
- Source
- hats
The Most/Aleph Zero bridge's receiveRequest distinguishes native ETH from ERC-20 tokens by comparing the destination token address to the configured WETH address, unwrapping WETH to native ETH whenever it matches. Because bridge-ins via sendRequest never re-wr …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Most--Aleph-Zero-Bridge-0xab7c1d45ae21e7133574746b2985c58e0ae2e61d/issues/34
- https://github.com/hats-finance/Most--Aleph-Zero-Bridge-0xab7c1d45ae21e7133574746b2985c58e0ae2e61d
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.