Executive brief
ZenHive mpp is a blockchain-based payment processing library used to verify and authenticate transactions. An unauthenticated attacker can bypass payment verification by replaying previously confirmed blockchain transfers, allowing them to obtain paid services or resources without actually making new payments.
Technical details
The vulnerability is a replay attack in the MPP.Methods.EVM.verify/2 function, which verifies payment proofs based on blockchain transaction hashes. The verification logic matches transfers solely on token, recipient address, and amount without binding the proof to the specific payment challenge or recording prior use. Additionally, the deduplication store keys on challenge.id, which is regenerated for every 402 response, allowing a single historical transfer from a public blockchain to satisfy multiple future payment charges. An attacker can read historical transfers from a public block explorer and replay them to gain unauthorized access to paid resources. This affects all versions from 0.3.0 before 0.6.3; a patch is available in 0.6.3 or later.
Affected products
- ZenHive mpp 0.3.0 to before 0.6.3
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 0.6.3