message-spoofing

1 article
sort: new top best
clear filter
0 7/10
incident-report

Scroll executed an emergency upgrade on April 25, 2025 to patch two critical vulnerabilities: a soundness bug in OpenVM 1.0.0's auipc opcode circuit (off-by-one in enumeration causing insufficient range checking) and a message spoofing vulnerability in the bridge's EnforcedTxGateway contract that could allow arbitrary token minting on L2.

Scroll OpenVM Axiom Immunefi WhiteHatMage Trail of Bits L1ScrollMessenger EnforcedTxGateway L2ScrollMessenger
forum.scroll.io · WhiteHatMage · 18 hours ago · details