All reports
mediumBridge exploitEVM-Solidity

The Graph: If L1GraphTokenGateway's `outboundTransfer` is called by a contract, the entire `msg.value` is blackholed, whether the ticket got redeemed or not

Payout
$0
Protocol
The Graph
Disclosed
Aug 7, 2026
Source
code4rena

The Graph's L1GraphTokenGateway.outboundTransfer, when bridging GRT to Arbitrum, passes the caller's own address as both the submission-refund and value-refund destination for the underlying retryable ticket. This is harmless for EOA callers because Ethereum a …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.