All reports
mediumBridge exploitEVM-Solidity

Centrifuge: `onlyCentrifugeChainOrigin()` can't require `msg.sender` equal `axelarGateway`

Payout
$0
Protocol
Centrifuge
Disclosed
Oct 11, 2023
Source
code4rena

Centrifuge's `AxelarRouter` implementation contained a flawed modifier `onlyCentrifugeChainOrigin` that strictly required `msg.sender` to be the `AxelarGateway` contract. However, Axelar's cross-chain message architecture does not invoke destination contract ` …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.