All reports
mediumLogic errorEVM-Solidity

Malda: mErc20Host: It is not possible to permissionlessly call "external" endpoints when source chain is Eth mainnet, because l1Inclusion flag cannot be set to true

Payout
$0
Protocol
Malda
Disclosed
Aug 14, 2025
Source
sherlock

Malda's host-side mErc20Host contract forces permissionless proof submitters (callers who are not proof/batch proof forwarders) to set the l1Inclusion journal flag. However, the zk coprocessor's proof-generation path panics for the Ethereum mainnet chain id, s …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.