kyc-aml

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A critical vulnerability in Mt Pelerin's bridge-protocol-v2 allowed attackers to drain contract funds by calling cancelOnHoldTransactions() with duplicate transaction arrays, exploiting a missing status check that would process the same transaction multiple times. The bug was responsibly disclosed and patched with a status verification check; no funds were lost.

Mt Pelerin Immunefi bridge-protocol-v2 ComplianceRegistry.sol cancelOnHoldTransfers
medium.com · unknown · 19 hours ago · details