solidity-quirk

1 article
sort: new top best
clear filter
0 8/10
vulnerability

Two high-severity denial-of-service vulnerabilities discovered in Stargate's LayerZero integration: (1) a Solidity try/catch quirk where calling non-contract addresses bypasses exception handling and permanently freezes message channels, and (2) a gas exhaustion attack leveraging excessive SSTORE operations (22.1k gas per operation) in the catch clause when storing malicious payloads, both capable of blocking bridged message delivery across chains.

Stargate LayerZero ULNv1 MPTValidator Immunefi Router Bridge Endpoint
trust-security.xyz · Trust Security · 17 hours ago · details