Optimism disclosed a critical vulnerability this week that could have let attackers forge refund payloads on the network. The bug lived in the SDM verify path — specifically the pre-Lagoon refund logic — and accepted fake refund requests without recomputing the state. The team said it patched the issue before any production chain was hit and that no funds were lost.
What the bug did
The vulnerability sat in what Optimism calls the SDM verify path, a sensitive piece of infrastructure that checks refund transactions. Normally the system recomputes the refund amount to make sure it matches the original deposit. But this bug skipped that recomputation, so a forged payload would pass verification. Anyone who found the hole could have drained funds from the bridge contract — at least in theory.
How it got fixed
The fix went in before the Lagoon upgrade reached production. That's key: Lagoon is Optimism's next major protocol update, and the vulnerable code was part of the older refund path that Lagoon replaces. The team caught the issue internally, patched it, and then posted the full disclosure on the Optimism governance forum. No outside researcher or exploit attempt triggered the fix — it was a proactive catch.
Why the disclosure matters
Publicly detailing a serious vulnerability after it's patched is still rare in crypto. Most teams quietly ship a fix and move on. Optimism's decision to lay out the technical specifics — the verify path, the refund logic, the pre-Lagoon context — gives other builders a concrete case study in what can go wrong. The timing isn't perfect: a disclosed vulnerability always raises questions about how many similar blind spots exist. But the team made clear the window for exploitation was zero.
The Lagoon upgrade is expected to go live in the coming weeks, and it eliminates the affected code entirely. For now, the disclosure stands as a reminder that even battle-tested rollups can have logic gaps — and that catching them before they're exploited is the whole game.




