Executive brief
ZenHive mpp is a cryptocurrency payment processor that validates transfers to unlock access to paid resources. An attacker can bypass authentication by replaying a legitimate transfer made by another customer, allowing unauthorized access to paid services without making a payment. The vulnerability stems from insufficient validation of transaction ownership when static memo values are configured, enabling attackers to reuse transaction hashes across different requests.
Technical details
The vulnerability is an authentication bypass in MPP.Methods.Tempo's transaction verification logic. When a static "memo" value is configured in method_config, the check_matched_memo_binding/3 function unconditionally returns a match and skips nonce-based transaction binding, relying only on token, recipient, amount, and static memo values. Since static memos are echoed in unauthenticated 402 responses and Tempo transfers are publicly visible on-chain, an attacker can capture any legitimate transfer matching these criteria, request a fresh challenge for the same route, and present the captured transaction hash as a type="hash" credential. The hash path performs no sender or signature verification, allowing an unauthenticated user to claim ownership of any observed transfer. This is fixed in version 0.6.4 and later.
Affected products
- ZenHive mpp 0.6.1 to 0.6.3
Timeline
- 2026-08-19: disclosed
- 2026: patched: Fixed in version 0.6.4