consensus-layer-attack

1 article
sort: new top best
clear filter
0 9/10
vulnerability

A critical type-confusion vulnerability in Polygon PoS's Heimdall validator software allowed attackers to bypass event validation through unverified log event decoding, potentially enabling rogue validators to inject fraudulent stake updates and compromise the $2B+ PoS bridge. The vulnerability existed in the UnpackLog function which failed to verify event type signatures before unpacking Ethereum logs.

Polygon PoS Heimdall Ethereum Cosmos Tendermint StakeManager StakingInfo Bor Immunefi MsgStakeUpdate SideHandleMsgStakeUpdate DecodeValidatorStakeUpdateEvent UnpackLog
asymmetric.re · Barracuda3172 · 17 hours ago · details