In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/babylonlabs-io/babylon/x/finality/types
to version 1.1.0 or higher.
Affected versions of this package are vulnerable to User Impersonation due to insufficient validation in the MsgCommitPubRandList
handler, combined with a lack of domain separation in signed messages. An attacker can store an invalid PubRand commitment by crafting the message parameters to exploit the signature replay vulnerability.