validator-compromise

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A vulnerability in Polygon's Heimdall validator software allowed rogue validators to forge Ethereum log events by exploiting improperly indexed log matching in the DecodeValidatorStakeUpdateEvent function, potentially enabling stake manipulation and fraudulent bridge transactions affecting $2B+ in locked assets. The flaw resided in the side-handler verification logic that failed to properly validate log authenticity when comparing transaction receipts against incoming Heimdall messages.

Polygon PoS Heimdall Ethereum StakeManager StakingInfo MsgStakeUpdate Immunefi Felix Wilhelm Bor Tendermint Cosmos
asymmetric.re · Barracuda3172 · 17 hours ago · details