GHSA-QPXH-FF8M-C62V: Gas Draining and Resource Exhaustion in ZenHive mpp Library
Vulnerability ID: GHSA-QPXH-FF8M-C62V
CVSS Score: 7.5
Published: 2026-09-25
A critical gas draining vulnerability exists in the ZenHive mpp (Multi-Payment Protocol) library prior to version v0.6.0. By omitting validation of EIP-2930 access lists in custom 0x76 transaction envelopes, the library allows malicious clients to pad transaction payloads with dummy addresses, draining the gas sponsor's hot wallet.
TL;DR
Unvalidated access list padding allows attackers to drain native tokens from sponsored gas wallets on EVM-compatible networks.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400, CWE-20
- Attack Vector: Network / Remote
- CVSS Score: 7.5 (High)
- Impact: Wallet Fund Depletion / Denial of Service
- Exploit Status: Proof of Concept available
Affected Systems
- ZenHive mpp (Multi-Payment Protocol) Elixir library
-
mpp: < 0.6.0 (Fixed in:
0.6.0)
Code Analysis
Commit: 5d6338e
Implement MPP.Methods.Tempo.FeePayerPolicy validation
Mitigation Strategies
- Upgrade ZenHive mpp library to v0.6.0 or higher
- Temporarily disable transaction fee sponsorship in application configuration
Remediation Steps:
- Update mix.exs with {:mpp, "~> 0.6.0"}
- Run mix deps.get and mix compile to pull the patched version
- Verify the fee payer policy config is enabled and active
References
Read the full report for GHSA-QPXH-FF8M-C62V on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)