Security Audit Flags Reentrancy and Access Control Risks in Polygon Bridge
A security audit of Polygon Bridge, which holds approximately $2.8 billion in total value locked, identified medium-to-high risks across reentrancy and access control dimensions, earning an overall risk score of 6.5 out of 10. Auditors found indirect reentrancy vulnerabilities in the ERC20, ERC721, and ERC1155 Predicate contracts, where malicious token callbacks could allow double-spending of exit proofs. A cross-chain reentrancy pathway was also identified, where a malicious Layer 2 contract could potentially re-enter the Layer 1 bridge during exit finalisation, risking token inflation or collateral loss. Additionally, over-privileged single-key admin accounts on both the RootChainManagerProxy and ChildChainManagerProxy lack multi-signature enforcement, meaning a compromised key could simultaneously pause the bridge and upgrade core logic. No critical instant-drain vulnerabilities were discovered, but auditors warned the identified issues could enable asset freezing, partial fund loss, or a full bridge-drain attack under a compromised admin scenario.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in