denial-of-service

11 articles
Sort: New Top Best
clear filter
0 6/10
Sui
vulnerability

A high-severity DoS vulnerability in Sui's Narwhal consensus layer allowed attackers to crash validator nodes via Out-of-Memory (OOM) attacks by sending a single malicious request with 1.2M certificate digests (37MB payload), bypassing the absence of response limits and timeout handling in the get_certificates() function. The vulnerability was patched by removing the vulnerable GetCertificates and GetPayloadAvailability handlers, with the researcher earning a $50,000 SUI bounty.

Sui Immunefi @F4lt Narwhal Bullshark Move MystenLabs
immunefi.com · unknown · 4 hours ago · details
0 2/10
bragging-post

A portfolio page showcasing multiple critical smart contract vulnerability disclosures across DeFi protocols (88mph, Polygon, KeeperDAO, Alchemix, Ondo Finance) and bug bounty wins totaling over $6.5M in rescued funds, with brief technical descriptions of UUPS proxy exploits, access control flaws, and token theft vulnerabilities.

88mph Polygon KeeperDAO Rivermen NFT OpenZeppelin abwagmi AxonsToken pxMythics Alchemix Ondo Finance Code4rena yAcademy Immunefi iosiro BSides Cape Town Underhanded Solidity Contest Curve Finance
ashiq.co.za · Ashiq Amien · 4 hours ago · details
0 7/10
vulnerability

A round-down arithmetic vulnerability in Astroport's Staking.rs contract allows an attacker to deflate the xASTRO token and break staking for all users by exploiting the absence of minimum liquidity requirements, potentially leading to governance control via vote monopolization.

Astroport ChainLight Immunefi Staking.rs xASTRO ASTRO Uniswap V2 SunSec DeFiHackLabs
defihacklabs.substack.com · ChainLight · 4 hours ago · details
0 8/10
vulnerability

Security researcher discovered two critical bugs in Cronos Gravity Bridge: (1) an incorrect ERC-20 deploy event check causing nonce mismatch that halts cross-chain transfers from Ethereum to Cronos, and (2) a malicious token that can disable the entire bridge. The vulnerabilities stem from inadequate validation in the MsgSubmitEthereumEvent handler and token supply checks.

Cronos Gravity Bridge Immunefi Sommelier Zellic Gravity.sol CosmosERC20 x/gravity
faith2dxy.xyz · Faith · 4 hours ago · details
0 8/10
vulnerability

Acala's Homa staking protocol contained an unbounded loop in the process_redeem_requests function that could be exploited by an attacker with 12,000+ DOT to create 22,000 redemption requests, causing the validator's on_initialize function to exceed block finalization time limits and halt the entire parachain's block production.

Acala Polkadot Homa Immunefi @Lastc0de Acala Foundation
immunefi.com · Lastc0de · 4 hours ago · details
0 8/10
vulnerability

A critical vulnerability in Axelar Network allowed attackers to force validators to miss votes by crafting transactions with excessive logs that exceed Tendermint's 1MB RPC request limit, leading to automatic Chain Maintainer deregistration and potential halt of cross-chain operations. The vulnerability has been patched via governance proposal 256 disabling the auto-deregistration mechanism.

Axelar Network Marco Hextor Immunefi AxelarGateway Tendermint Cosmos SDK governance-proposal-256
marcotnunes.com · Marco Nunes · 4 hours ago · details
0 8/10
bug-bounty

Researcher disclosed two critical bugs in Sei Network's Cosmos blockchain: (1) an ABCI EndBlocker panic triggered via vesting accounts that would halt the chain, and (2) a balance transfer vulnerability in EVM integration allowing arbitrary fund transfers. Both were caught pre-mainnet and awarded $75k and $2M respectively.

Sei Network Sei Foundation Cosmos SDK Geth Trail of Bits Immunefi CVE-2024-XXXXX (implied but not stated)
usmannkhan.com · usmannk · 4 hours ago · details
0
postmortem

Story Network's postmortem analysis reveals two critical vulnerabilities discovered during mainnet launch. The first issue allowed attackers to create arbitrarily large EVM transaction payloads (>4MB) that would cause validator crashes and network shutdown through JSON marshalling inefficiencies and inadequate block size validation inherited from Octane codebase.

Story Network Story Foundation Cantina Octane Omni Geth CometBFT
story.foundation · WhiteHatMage · 4 hours ago · details
0
vulnerability

A denial-of-service vulnerability in LayerZero's ONFT (ERC721) implementation allows attackers to freeze cross-chain token transfers by passing a malicious receiver contract that exhausts gas in the onERC721Received() callback, causing the message to block indefinitely at the Endpoint level. The issue stems from NonBlockingLzApp's insufficient gas reservation (1/64 of gasLimit) to handle failed message storage when all allocated gas is consumed.

LayerZero Stargate Immunefi OpenZeppelin ULNv1 NonBlockingLzApp ONFT OFT ERC721 ERC20
trust-security.xyz · Trust Security · 4 hours ago · details
0
vulnerability-disclosure

Trust Security discovered a class of DOS vulnerabilities affecting 100+ projects that abuse the frontrunnable nature of EIP-2612 Permit function when composed with other contract logic. The vulnerability allows attackers to force transaction reverts by front-running permit() calls, causing griefing attacks that block normal function execution, with $50k in bounties awarded across 15 projects.

EIP-2612 ERC20 Permit OpenZeppelin AAVE The Graph Uniswap-V2 Ribbon Pods Nexus Mutual Mars Gro Ease Kyber DeBridge SpookySwap Angle Morpho Immunefi 100proof Trust Security ERC20 Governance
trust-security.xyz · Trust Security · 4 hours ago · details
0
vulnerability

A critical bug in Thena's merge() function fails to reset the supply variable when merging two veNFTs, allowing attackers to artificially inflate supply and manipulate weekly emissions, reduce reward distribution, or cause DOS attacks against the protocol. The vulnerability was disclosed to Thena via Immunefi and rewarded $20k.

Thena immunefi trust__90
zzykxx.com · zzykxx · 4 hours ago · details