All reports
criticalBridge exploitEVM-Solidity

Bridge withdrawal proof accepts empty Merkle path

Payout
$1.8M
Protocol
L2 Canonical Bridge
Disclosed
Jun 2, 2022
Source
immunefi

A flawed proof verification mechanism in an L2 canonical bridge contract permitted withdrawal validation using an empty Merkle proof array. When no proof elements were supplied, the verification function failed to iterate and directly compared the unhashed wit …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.