Beginner FriendlyFoundryBridge
100 EXP
View results
Submission Details
Severity: high
Invalid

SIGNATURE_NO_VERSION_PINNING

Summary

Same signature can be used on multiple versions of the contract

Vulnerability Details

When new version of the contract is deployed, the same signature is valid for both

Impact

Using one signature to withdraw money from different versions of the protocol

Tools Used

Recommendations

Add contract / protocol version to the message to sign

Updates

Lead Judging Commences

0xnevi Lead Judge
almost 2 years ago
0xnevi Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Too generic

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.