Beginner FriendlyFoundryBridge
100 EXP
View results
Submission Details
Severity: high
Invalid

Signature malleability in sendToL1 function.

Summary

The function sendToL1 can be tricked that the signer is other that the real signer

Vulnerability Details

ECDSA signatures are naturally malleable and can be modified while maintaining validity.
To get another signature that recovers to the same signer we flip the S and V

Impact

High as it will lead to stolen funds.

Tools Used

Manual review

Recommendations

Updates

Lead Judging Commences

0xnevi Lead Judge
almost 2 years ago
0xnevi Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Too generic

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.