All reports
mediumLogic errorEVM-Solidity

ZetaChain Cross-Chain: Incorrect de-structuring of parse_intent()'s return value will trigger unexpected operations

Payout
$0
Protocol
ZetaChain Cross-Chain
Disclosed
May 12, 2025
Source
sherlock

ZetaChain's TON Gateway contract contains a FunC tuple de-structuring error in `recv_internal()`: it binds the first element of `parse_intent()`'s `(slice, (int, int))` return — the remaining message body slice — to an `int op` variable instead of reading the …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.