gas-station-network

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

Enzyme Finance had a critical missing privilege check vulnerability in its GasRelayPaymasterLib contract where the paymaster failed to validate the trusted forwarder's address, allowing attackers to bypass signature verification and drain the Vault by crafting malicious relayCall transactions. Whitehat rootrescue discovered and responsibly disclosed the bug, earning a $400,000 bounty.

Enzyme Finance Immunefi rootrescue GasRelayPaymasterLib GasRelayPaymasterFactory GasRelayRecipientMixin RelayHub
medium.com · rootrescue · 22 hours ago · details