antehandler

1 article
sort: new top best
clear filter
0 7/10
vulnerability

A vulnerability in Cronos/Ethermint allowed attackers to construct MsgEthereumTx messages without ExtensionOptionsEthereumTx, bypassing the EthGasConsumeDecorator handler and enabling theft of transaction fees from the current block through false gas refunds. The bug was fixed in v0.6.5 by adding validation to ensure MsgEthereumTx is properly wrapped.

Cronos Ethermint zb3 Immunefi Cosmos SDK Tendermint MsgEthereumTx ExtensionOptionsEthereumTx EthGasConsumeDecorator GHSA-f854-hpxv-cw9r
medium.com · zb3 · 23 hours ago · details