Skip to content
Cosmopediaby Unity Nodes
DiscussionsSecurity[critical] EVM Precompiled contract bug allowing unlimited token mintForum ↗

[critical] EVM Precompiled contract bug allowing unlimited token mint

Security2 posts927 views6 likesLast activity Jul 2024
ZA
ZacCheahOP
Jul 2024 6

Background This vulnerability is found in precompiled contract module. It allows attackers to infinitely increase their delegation without deducting their token balance, in other words, the attacker is able to mint tokens infinitely. Who was affected (not anymore) This vulnerability has been found and fixed in Evmos and FunctionX/PundiX. FunctionX/PundiX discovered this bug and patched it in June 2024. Evmos team discovered this bug independently and patched it yesterday on 4 July 2024. Another precompile implementor chain Cronos do NOT have this bug at all. Well done ser. Other chains using similar implementations are strongly advised to check and patch. Who is still affected If a Cosmos-SDK chain implements a staking precompiled contract with delegate function. As of 5 July GMT+8 there are at least two other Cosmos-SDK mainnet known to have this bug, they are comparitively less big projects. Even if projects did NOT fork from Evmos or FunctionX/PundiX it is still possible to have this bug fi precompile staking is implemented, as chances are dev will use try/catch to handle error. Causes Before we go deep into the vulnerability, let’s…

Excerpt (1193 of 5319 characters). Read the whole post on the forum ↗

GO
Govmos
Jul 2024

It was interesting to read through this very well described post. Thank you for this contribution to the forum!

← Back to Discussions