bug-bounty498
google355
xss301
microsoft298
facebook263
rce211
exploit200
malware171
apple164
cve136
account-takeover115
bragging-post102
privilege-escalation95
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain68
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering55
react52
access-control51
input-validation49
cross-site-scripting48
aws47
cloudflare47
docker46
web-security46
lfi46
sql-injection45
smart-contract45
ethereum44
web-application44
web343
defi43
ctf43
oauth43
node43
pentest40
race-condition39
idor37
open-source37
cloud37
burp-suite36
info-disclosure36
auth-bypass35
0
7/10
vulnerability
A critical NFT bridge vulnerability in L1/L2 ERC721Bridge contracts allows attackers to steal deposited NFTs by exploiting inadequate token validation—an attacker can create a worthless L2 token, call withdrawTo() to burn it, and trigger finalizeERC721Withdrawal() on L1 without proper L1-L2 token correspondence checks, enabling theft of any NFT in the bridge contract.
smart-contract-vulnerability
nft-bridge
cross-chain-bridge
input-validation
access-control
layer2
optimistic-rollup
erc721
theft
unauthorized-withdrawal
L1ERC721Bridge
L2ERC721Bridge
IL2StandardERC721
Immunefi
Heuss