GHSA-f854-hpxv-cw9r

    Dashboard / Vulnerabilities / GHSA-f854-hpxv-cw9r

    GHSA-f854-hpxv-cw9r

    Published: 6 Jan 2022Last Modified: 8 Jul 2026

    Summary: Drainage of FeeCollector's Block Transaction Fees in cronos

    Details: ### Impact In Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. ### Patches This problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. ### Workarounds There are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. ### Credits Thank you to @zb3 for reporting this issue on [Cronos Immunefi Bug Bounty Program](https://immunefi.com/bounty/cronos/), to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. ### For more information If you have any questions or comments about this advisory: * Open a discussion in [crypto-org-chain/cronos](https://github.com/crypto-org-chain/cronos/discussions/new) * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: github.com/crypto-org-chain/cronos

    Purl: pkg:golang/github.com/crypto-org-chain/cronos

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.6.5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-f854-hpxv-cw9r | CVE-DB