Today, in coordination with
@ethereumfndn, we're disclosing a high-severity DoS attack affecting the core of ERC4337 account abstraction. Users are strongly encouraged to migrate to v0.9 wallets where the issue is mitigated.
This previously unseen attack vector weaponizes various safety checks including reentrancy guards which are ubiquitous in modern DeFi infrastructure, to deny withdrawals and disrupt core functionality for AA users. From our research, a meaningful share of AA DeFi activity could be disrupted.
Huge thanks to the EF for handling the issue responsibly and granting us a $50k bounty, the maximum high-severity award. We've also reached out to major affected dApps in order to guard their AA users. We'd like to commend projects that took quick action and upheld their commitment both to their users and the whitehat community - an additional $59.5k was granted by affected dApps. Full disclosure of relevant DeFi products and their responses will be released soon.
Additional details including root cause analysis can be found in the EF disclosure below. TrustSec is determined to continue safeguarding the Ethereum ecosystem, even from the most surprising attack vectors.