You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Giving the spec a quick glance, I don't see a check enforcing that the receiving port address is the host chain port. This means a malicious ics27 module (host chain) could trick the controller chain into accidentally trying to execute a transaction. I'm not sure if it is exploitable in any way, but there should probably be a check enforcing that controller chain ports cannot receive packets
The text was updated successfully, but these errors were encountered:
mpoke
changed the title
Interchain Accounts allows packets to be received on controller side
ICS27: Interchain Accounts allows packets to be received on controller side
Mar 17, 2022
Giving the spec a quick glance, I don't see a check enforcing that the receiving port address is the host chain port. This means a malicious ics27 module (host chain) could trick the controller chain into accidentally trying to execute a transaction. I'm not sure if it is exploitable in any way, but there should probably be a check enforcing that controller chain ports cannot receive packets
The text was updated successfully, but these errors were encountered: