fund-transfer

2 articles
sort: new top best
clear filter
0 5/10
bug-bounty

A researcher discovered a critical $150,000 Evmos vulnerability by simply reading Cosmos documentation—sending funds to the distribution module account (which should be blocklisted) triggered invariant violations that halted the entire blockchain and all dependent dApps.

Evmos Cosmos Immunefi jayjonah.eth x/bank module distribution module
medium.com · jayjonah.eth · 15 hours ago · details
0 9/10
vulnerability

Security researcher discovered two critical bugs in Sei Network's layer-1 blockchain: (1) an ABCI panic in the EVM EndBlocker triggered by vesting accounts with locked funds, causing chain halts, and (2) a balance handling vulnerability allowing arbitrary fund transfers via negative number handling in SubBalance/AddBalance functions. Both bugs were caught pre-mainnet and rewarded at $75,000 and $2,000,000 respectively.

Sei Network Sei Foundation Cosmos SDK Geth Trail of Bits Immunefi CVE-2024 (implied, not explicitly stated)
usmannkhan.com · usmannk · 15 hours ago · details