callback-reentrancy

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A denial-of-service vulnerability in LayerZero's ONFT (ERC721) implementation allows attackers to freeze cross-chain token transfers by exploiting uncapped gas usage in the ERC721 callback mechanism. When a malicious receiver contract exhausts the gas allocation during _safeMint(), it causes the nonblockingLzReceive() to fail with insufficient gas to store the failure, permanently blocking the message queue until manual intervention.

LayerZero Stargate ONFT OFT Immunefi OpenZeppelin NonBlockingLzApp ULNv1
trust-security.xyz · Trust Security · 17 hours ago · details