Announcement[Hexcast]
Discover EigenLayer Sidecar Bug Before Exploitation
EigenLayer's sidecar had a critical division-by-zero bug in reward calculations caused by zero-duration rewards. The RewardsCoordinator.sol contract allowed duration=0 via require(duration % CALCULATION_INTERVAL_SECONDS == 0). Sidecar's operatorDirectedOperatorSetRewardSubmissions.go lacked validation, causing SQL queries (1_goldActiveRewards.go, 7_goldActiveODRewards.go, 11_goldActiveODOperatorSetRewards.go) to fail, risking DoS. Issue was fixed before exploitation.
Ethereum ecosystem intelligence