{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/confidential-contracts--0.3.2--0.4.0-rc.0--0.4.2--0.5.0-rc.0--0.5.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["confidential-contracts (\u003c 0.3.2, \u003e= 0.4.0-rc.0 \u003c 0.4.2, \u003e= 0.5.0-rc.0 \u003c 0.5.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","smart-contract","crypto","exfiltration"],"_cs_type":"advisory","_cs_vendors":["OpenZeppelin"],"content_html":"\u003cp\u003eThe OpenZeppelin confidential-contracts library contains critical logic errors in its handling of FHE (Fully Homomorphic Encryption) handles, specifically within the \u003ccode\u003eVestingWalletConfidential\u003c/code\u003e and \u003ccode\u003eERC7984\u003c/code\u003e implementations. These flaws allow untrusted external parties to bypass access control list (ACL) verification when consuming handles returned during contract operations.\u003c/p\u003e\n\u003cp\u003eIn the \u003ccode\u003eVestingWalletConfidential\u003c/code\u003e contract, a malicious ERC-7984 token can provide an alternative encrypted \u003ccode\u003eeuint64\u003c/code\u003e handle during a \u003ccode\u003erelease\u003c/code\u003e call. Because the contract fails to verify that the token has the necessary ACL authorization to access or return that specific handle, the contract inadvertently grants the caller access to the handle, leading to unauthorized data disclosure. A similar vulnerability exists in the \u003ccode\u003eERC7984\u003c/code\u003e transfer callback, where a malicious recipient can return an arbitrary \u003ccode\u003eebool\u003c/code\u003e handle during an \u003ccode\u003eonConfidentialTransferReceived\u003c/code\u003e call. By manipulating the refund logic, an attacker can extract the plaintext of the chosen \u003ccode\u003eebool\u003c/code\u003e handle. These issues allow for unauthorized information retrieval from within the FHE environment, though they do not permit the theft of funds.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects users and protocols relying on the OpenZeppelin confidential-contracts library to manage private FHE-encrypted data. An attacker can gain unauthorized access to private \u003ccode\u003eeuint64\u003c/code\u003e and \u003ccode\u003eebool\u003c/code\u003e handles associated with the target wallet or token transactions. This results in the exposure of confidential data stored within the FHE encrypted state. While the impact is limited to information disclosure and does not allow for direct theft or draining of assets, it compromises the confidentiality guarantees of the smart contracts involved.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003econfidential-contracts\u003c/code\u003e library to versions 0.3.2, 0.4.2, or 0.5.2 immediately to apply the required ACL validation patches.\u003c/li\u003e\n\u003cli\u003eAudit all custom implementations of \u003ccode\u003eIERC7984Receiver\u003c/code\u003e to ensure that callback logic does not blindly process encrypted handles returned by untrusted callers.\u003c/li\u003e\n\u003cli\u003eReview smart contract interaction logs to identify any anomalous calls to \u003ccode\u003erelease\u003c/code\u003e or \u003ccode\u003eonConfidentialTransferReceived\u003c/code\u003e involving unknown or non-standard token addresses that may have been used to probe for handle leakage.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T02:07:35Z","date_published":"2026-09-26T02:07:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openzeppelin-confidential-contracts/","summary":"The OpenZeppelin confidential-contracts library is vulnerable to private data leakage due to improper validation of encrypted handles returned by untrusted ERC-7984 tokens and recipients.","title":"Information Disclosure in OpenZeppelin Confidential Contracts","url":"https://feed.craftedsignal.io/briefs/2026-09-openzeppelin-confidential-contracts/"}],"language":"en","title":"CraftedSignal Threat Feed - Confidential-Contracts (\u003c 0.3.2, \u003e= 0.4.0-Rc.0 \u003c 0.4.2, \u003e= 0.5.0-Rc.0 \u003c 0.5.2)","version":"https://jsonfeed.org/version/1.1"}