cross-chain-vulnerability

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A critical vulnerability in Arbitrum's DelayedInbox bridge contract allowed attackers to reinitialize the contract and set a malicious bridge address due to an uninitialized storage slot combined with a gas optimization that removed a redundancy check, enabling theft of all deposited ETH.

Arbitrum Nitro DelayedInbox.sol TransparentUpgradeableProxy Optimism 0xriptide ImmuneFi
medium.com · riptide · 17 hours ago · details