Ethereum Hyperbridge HandlerV1 contract was subjected to an MMR proof replay attack, resulting in a loss of approximately $242k

Gate News message. On April 13, according to BlockSec monitoring, the Hyperbridge HandlerV1 contract on Ethereum was hit by an MMR proof replay attack, resulting in losses of about $242k. The vulnerability allows attackers to replay previously accepted proofs and pair them with newly constructed requests, enabling privileged operations (for example, changing administrator permissions) to profit. In HandlerV1, replay protection only checks that the request commitment (request.hash()) has not been used before; however, the proof verification process did not bind the submitted request payload to the verified proof. Due to this disconnect, effective historical proofs can be reused with different malicious requests.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments