Biconomy: Nexus

HardhatFoundry
30,000 USDC
Submission Details
Severity: low
Invalid

K1Validator does not check and update the nonce of the Account , which allow signature replay attacks , which leads to drain all the funds of the account

Updates

Lead Judging Commences

0xnevi Lead Judge 4 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement
Assigned finding tags:

finding-validateUserOp-nonce

Invalid, `validateUserOp` can only be called via the `EntryPoint` contract, wherein the [nonce is appropriately updated and checked](https://github.com/eth-infinitism/account-abstraction/blob/develop/contracts/core/EntryPoint.sol#L650-L652)

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.

Cyfrin
Updraft
CodeHawks
Solodit
Resources