Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration
High severity
GitHub Reviewed
Published
Dec 12, 2025
in
babylonlabs-io/finality-provider
•
Updated Dec 12, 2025
Package
Affected versions
<= 1.0.3
Patched versions
None
Description
Published to the GitHub Advisory Database
Dec 12, 2025
Reviewed
Dec 12, 2025
Last updated
Dec 12, 2025
Summary
The anti-slashing is not effective if the attacker can access EOTS manager endpoints.
Impact
If the EOTS manager endpoints are open to public without HMAC protection, the attacker can manually cause slashing of the finality provider through the RPC endpoints
References