DeFiLayer 1Layer 2
14,723 OP
Submission Details
Severity: medium
Invalid

Replay/Outdated Proofs Vulnerability in Scrvusd Verifier Contracts

Author Revealed upon completion
Updates

Lead Judging Commences

0xnevi Lead Judge 13 days ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement
Assigned finding tags:

[invalid] finding-replay-proof-lack-nonce

- All proof generated within `_proof_rlp` is generated via the off-chain prover, so there is no concrete proof that this proofs are non-unique. - All state roots and proofs must be verified by the OOS `StateProofVerifier` inherited as `Verifier`, so there is no proof that manipulating proofs can successfully pass a price update

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.

Cyfrin
Updraft
CodeHawks
Solodit
Resources