smart-contract-interaction

1 article
Sort: New Top Best
clear filter
0 8/10
vulnerability

A critical type-confusion vulnerability in Polygon's Heimdall consensus layer allowed rogue validators to forge StakeUpdate events without proper type verification, potentially enabling validator takeover and fraudulent bridge events affecting $2B+ in locked assets. The flaw exploited incomplete event signature validation in the UnpackLog function, which failed to verify the event topic hash.

Polygon Heimdall Ethereum StakeManager StakingInfo Cosmos Tendermint Bor geth MsgStakeUpdate Immunefi
asymmetric.re · Barracuda3172 · 5 hours ago · details