Reproduced Exploit

Maia DAO — Adversary can poison depositNonce via retrieveDeposit and lock user deposits

1. Attacker calls retrieveDeposit(60) with no ownership check.\n2. Root marks nonce 60 executed.\n3. User deposit with nonce 60 is rejected on root; tokens locked on branch.

May 2023Otheruntagged2 min read

Chain

Other

Category

untagged

Date

May 2023

Source

AuditVault

EVM Playground

Source-level debugger — step opcodes and Solidity in sync

evm-hack-analyzer

The attack is replayed in an in-browser EVM preloaded with the exact dumped fork state. The execution tree shows every call; step by Solidity line or by opcode across all depths — source, Stack, Memory, Storage, Balances (native / ERC-20 / NFT), Transient storage and Return value stay in sync. Click a tree node, opcode, or source line to jump. No backend, no live RPC.

Loading fork state…

Source & credit. Reproduction of a public audit finding curated by AuditVault — the original finding: 26042-h-08-due-to-inadequate-checks-an-adversary-can-call-branchbr. Standalone Foundry PoC and full write-up: 26042-h-08-due-to-inadequate-checks-an-adversary-can-call-branchbr_exp in the evm-hack-registry mirror.


Vulnerability classes: see taxonomy below

Reproduction: a self-contained Foundry PoC that compiles & runs in an isolated project with only forge-std — no fork, no RPC, no anvil_state. Full trace: output.txt. PoC: test/26042-h-08-due-to-inadequate-checks-an-adversary-can-call-branchbr_exp.sol.


Key info#

ImpactHIGH — Permissionless retrieveDeposit marks future nonce executed; user deposit of 1000 DEP locked on branch
ProtocolMaia DAO
FindingCode4rena · reporter xuwinnie
Reporthttps://code4rena.com/reports/2023-05-maia
SourceAuditVault
StatusAudit finding — reproduced as a standalone local PoC.
Compiler^0.8.24 (PoC)

This is an audit finding, not a historical on-chain incident.


TL;DR#

  1. Attacker calls retrieveDeposit(60) with no ownership check.\n2. Root marks nonce 60 executed.\n3. User deposit with nonce 60 is rejected on root; tokens locked on branch.

Diagrams#

flowchart TD A[Setup vulnerable state] --> B[Trigger vulnerable path] B --> C[Harm asserted in run]

Impact#

Permissionless retrieveDeposit marks future nonce executed; user deposit of 1000 DEP locked on branch

Sources#


Sources & further analysis#

Reproductions & code

Alerts & third-party analyses

  • Web3Sec X hacked database: search.
  • Rekt leaderboard: search.
  • Solodit incident search: search.

These dashboards index community alerts tweets, post-mortems, and independent write-ups. Reach them through the protocol name above to cross-check this reproduction against other analyses.