optimistic-rollup

1 article
sort: new top best
clear filter
0 7/10
-
vulnerability

A critical NFT bridge vulnerability in L1/L2 ERC721Bridge contracts allows attackers to steal deposited NFTs by exploiting inadequate token validation—an attacker can create a worthless L2 token, call withdrawTo() to burn it, and trigger finalizeERC721Withdrawal() on L1 without proper L1-L2 token correspondence checks, enabling theft of any NFT in the bridge contract.

L1ERC721Bridge L2ERC721Bridge IL2StandardERC721 Immunefi Heuss
medium.com · Heuss · 23 hours ago · details