Executive brief
ZenHive's mpp (Memo Payment Protocol) is a blockchain payment system that sponsors transaction costs for users. A vulnerability in the fee-payer validation logic allows an unauthenticated attacker to exploit sponsored payments by embedding additional authorization requests alongside normal payment calls. This causes the sponsor to pay significantly inflated gas fees (up to ~39x higher) while the attacker gains a free access key to spend tokens on the blockchain.
Technical details
The vulnerability exists in ZenHive mpp's FeePayerPolicy.measure/3 function in lib/mpp/methods/tempo/fee_payer_policy.ex. The code validates gas limits, fee budgets, validity windows, and access lists in client-signed 0x76 envelopes, but fails to check for the optional key_authorization field. An unauthenticated remote attacker can attach a fully signed key authorization request to provision new access keys with token spending limits on their own account within a normal sponsored payment. The key provisioning and limit entries are stored as persistent state writes that are billed as intrinsic gas to the sponsor, bounded only by the gas_limit ceiling. At baseline (one key with three token limits), this inflates costs from ~46,587 gas to ~1,808,700 gas while the attacker retains a valid access key at no cost. The issue affects versions 0.2.0 through 0.16.0; version 0.16.1 and later contain fixes.
Affected products
- ZenHive mpp 0.2.0 through 0.16.0
Timeline
- 2026-09-06: disclosed