PT-2025-31154 · Polkadot · Polkadot Frontier

Published

2025-07-28

·

Updated

2025-07-28

·

CVE-2025-54429

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Polkadot Frontier versions prior to 0822030
Description Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The implementation of CallableByContract incorrectly identified contract addresses running under CREATE or CREATE2 as externally owned accounts (EOA) instead of correctly identifying them as contract accounts. This issue affects users utilizing custom precompile implementations that rely on distinguishing between AddressType::EOA and AddressType::Contract. The vulnerability is not directly exploitable in the predefined precompiles within Frontier.
Recommendations Update Polkadot Frontier to version 0822030 or later.

Exploit

Fix

Incorrect Type Conversion or Cast

Weakness Enumeration

Related Identifiers

CVE-2025-54429
GHSA-FR62-PPWC-MC2H

Affected Products

Polkadot Frontier