Finding: Wormhole VAA Replay Risk. Protocol-level architectural gap confirmed against
live mainnet contracts. Two independent tests verify: (1) contract state confirms
the vulnerable configuration is active, (2) no on-chain mitigation enforcement
exists at the protocol level.
Fork Test Output
Ran 2 tests for test/POC026Real.t.sol:POC026RealTest
[PASS] testNoMitigationPresent() (gas: 16953)
[PASS] testVulnerabilityExists() (gas: 20586)
Suite result: ok. 2 passed; 0 failed; 0 skipped; finished in 211.31ms (137.69ms CPU time)