Highlights
Denial of Service: 53 prior fixes. Scrutinize any change in this area.
proxyd: most-fixed (13 issues). Treat as high-risk during review.
96 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Auth Bypass: A critical failure in target contract validation allowed spoofing of arbitrary L2 accounts by targeting sensitive on-chain messaging functions. This could lead to unauthorized L2 message execution.
Denial of Service: Lack of EIP-150 compliant gas validation inside try/catch blocks executing external calls enabled malicious actors to trigger out-of-gas manipulation on state transitions, forcing contract execution stalls.
Reentrancy: The WithdrawalsRelay was vulnerable to reentrancy attacks, allowing attackers to perform nested execution of withdrawals before states are updated, bypassing Checks-Effects-Interactions boundaries.