
@Phalcon_xyz @hyperbridge additionally there's a critical Consensus Signature Bypass (CVE-2025-24800) `handleConsensus()` calls `IConsensus(host.consensusClient()).verifyConsensus()`. There's a known critical bug in ismp-grandpa < v15.0.1 where the verifier ONLY accepts INVALID signatures.
Post summary
The tweet highlights a critical consensus signature bypass vulnerability (CVE‑2025‑24800) in ismp‑grandpa versions below 15.0.1, noting that the verifier incorrectly accepts only invalid signatures.
