transaction-tampering

1 article
sort: new top best
clear filter
0 7/10
vulnerability

zkSync Lite suffered a critical vulnerability in its packed floating-point format implementation where unconstrained witness allocation in the parse_with_exponent_le function allowed attackers to generate valid proofs with arbitrary mantissa values, enabling unauthorized token minting, freezing, and transaction tampering. The vulnerability was patched by enforcing constraints on mantissa calculations using an into_allocated_num method.

zkSync Lite zkSync Era LonelySloth Immunefi franklin-crypto ZK Rollup CVE-2023-XXXXX
medium.com · LonelySloth · 22 hours ago · details