Security Review Flags High-Risk Upgrade Vulnerabilities in Grove Finance Protocol
A security review dated September 30, 2026, assessed Grove Finance, a multi-chain yield-aggregation platform with approximately $1.27 billion in total value locked across Ethereum and Layer 2 networks. Researchers identified two high-criticality vulnerabilities: storage-layout collisions that could overwrite treasury addresses during contract upgrades, and unrestricted delegatecall usage in L2 adapters that could allow attackers to seize full control of the proxy. Additional medium-severity issues include a governance timelock bypass enabling near-instant upgrades, a cross-chain bridge protected only by a replaceable multi-signature scheme, and missing initializer guards that leave certain contracts open to re-initialization attacks. The protocol received an overall risk score of 7 out of 10, reflecting solid engineering offset by significant weaknesses in its upgrade architecture. Reviewers warned that these flaws could be exploited during either scheduled or emergency upgrades, potentially exposing hundreds of millions of dollars to attackers.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in