Biconomy: Nexus

HardhatFoundry
30,000 USDC
Submission Details
Severity: high
Invalid

The `K1Validator` omits the Nexus account address in the signature verification within the `isValidSignatureWithSender` function when it got called in `_enableMode` function , enabling replay attacks across multiple accounts owned by the same user.

Updates

Lead Judging Commences

0xnevi Lead Judge
4 months ago
0xnevi Lead Judge 4 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.

Cyfrin
Updraft
CodeHawks
Solodit
Resources