What happened

Hydra shipped a security-advisory fix for a permissionless-fanout flaw affecting how a head validator checked its trusted setup. The fix binds the canonical CRS trusted-setup datum on-chain through its BLAKE2b-256 content hash and rejects non-canonical setups.

Before the change, a substituted structured reference string with a known tau could satisfy the fanout membership check for any subset. The supplied record says that path could redirect a Hydra head’s whole balance, even though value conservation alone still held.

Why it matters

Fanout is permissionless, so the validator needed to establish not only that value was conserved, but also which outputs a fanout could pay. Binding the canonical CRS datum makes that trusted-setup choice part of the validator’s safety condition.

For Hydra operators and builders, the practical point is that this was described as a whole-head-balance risk within Hydra, an L2 protocol. The supplied evidence does not describe an issue in the Cardano base ledger.

What to watch

The record describes a red test, the validator fix, a single-source-of-truth hardening pass, and a merge labeled “Security advisory fix.” It also links the work to Hydra 2.3.0.

The next receipt to watch is confirmation that a Hydra head is running the CRS-datum-bound validator associated with 2.3.0. The supplied record says the protection applies only to heads using patched scripts.

What to watch

Watch for Hydra 2.3.0 adoption and confirmation that heads run the CRS-datum-bound validator.

Sources and limits

Upstream references and independent checks

Digest dated 2026-07-16 · upstream model claude-sonnet-4-6. Direct links are matched to all 4 upstream source IDs.

  1. 1
    Bind canonical CRS datum on-chain to close permissionless fanout fund…Direct upstream source · 9da56a532bb3af41f6cd68fa16f4f7fb625e9c97
  2. 2
    Merge commit from forkDirect upstream source · 0ff46d764ba50d57e37777e1b54381b01a427b25
  3. 3
    Red test - altering the crs datum allows for fund theft on FanoutDirect upstream source · ca214d26309c09b5b5c52ab6bc75c1aabf515583
  4. 4
    Derive canonical CRS datum hash from the embedded setup instead of ha…Direct upstream source · ed7d885ebd57444f50065ddb132e2dc956f957cc
Continue reading
  1. 1
  2. 2

This Research brief was generated by Terra from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: The evidence is limited to four official Hydra development-source records; it reports no in-the-wild exploitation or head draining.