Executive brief
A vulnerability in the ZenHive mpp Elixir library allows attackers to drain the digital wallet used by the server to pay for transaction fees. By submitting specially crafted payment requests that are designed to fail just before completion, an attacker can force the server to pay for 'burned' gas while the attacker pays nothing. This can lead to a total depletion of the server's funds, preventing legitimate users from making payments.
Technical details
The vulnerability exists in the MPP.Methods.Tempo payment method when configured with fee_payer: true. The library co-signs and broadcasts client-supplied EVM transactions without validating that the gas_limit is sufficient for the transaction to succeed. An attacker can provide a gas_limit slightly below the required threshold, causing the transaction to revert after consuming gas; the fee-payer wallet is charged for this burned gas while the attacker incurs no cost. The issue also affects the 'optimistic' path (wait_for_confirmation = false) because its simulation via eth_call omits the gas parameter, failing to detect out-of-gas conditions. A fix is available in version 0.6.0.
Affected products
- ZenHive mpp from 0.2.0 before 0.6.0
Timeline
- 2026-06-24: patched: Fix committed to repository
- 2026-07-17: advisory: NVD and CNA advisory published