homa-module

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A denial-of-service vulnerability in Acala's Homa module allowed attackers with 12,000+ DOT to halt block production by creating 22,000 redemption requests that exceeded processing time limits during the weekly on_initialize function call. The vulnerability stemmed from unbounded iteration over a RedeemRequests map with no size constraints, enabling attackers to temporarily halt the entire parachain with only gas fees as expense.

Acala Polkadot Homa Immunefi @Lastc0de DOT LDOT
immunefi.com · Lastc0de · 17 hours ago · details