wevm / wevm/mppx

Support third-party delivered payments (bridge/solver `Transfer.from !== receipt.from`)

Open
#284 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
176
Forks
66
Avg merge
1d 1h
Merged PRs (30d)
52

Description

Check existing issues
Describe the bug

Problem

type="hash" verification in tempo.charge() checks that Transfer.from === receipt.from via assertTransferLogs. This fails when a third party (bridge solver, payment processor) delivers funds on behalf of the payer.

Code: src/tempo/server/Charge.tsassertTransferLogs

if (!TempoAddress.isEqual(log.args.from, parameters.sender)) return false
// where sender = receipt.from

Proof

Verified against a real Relay bridge fill on Base (BaseScan):

receipt.from:  0x728f51950ff096dc03a48f5e83f45ac8bb75f500  (caller EOA)
Transfer.from: 0xf70da97812cb96acdf810712aa562db8dfa3dbef  (Relay Solver)
Match? false → verification fails

The solver holds the tokens and is the from in the ERC-20 Transfer event, but a different EOA submits the transaction. This pattern is standard across bridge protocols — the authorized caller and the token source are different addresses.

Use Case

Cross-chain MPP payments: an agent pays on chain A, a bridge solver delivers to the service on chain B. The service's mppx verification needs to accept the fill transaction as valid payment.

This applies to any bridge (Relay, Across, Stargate, etc.), payment processor, or custodial service that delivers funds on behalf of a payer.

Suggested Direction

A credential type that verifies the transfer landed on-chain (correct token, recipient, amount) without requiring Transfer.from === receipt.from. All other security layers (HMAC challenge binding, expiry, replay protection) remain unchanged.

Happy to discuss the approach and contribute a PR.

Package Version

0.5.3

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in src/tempo/server/Charge.ts at assertTransferLogs and trace the type="hash" verification path. Review how the existing checks bind the transfer to the receipt, then verify that the intended behavior accepts third-party delivery while retaining token, recipient, amount, HMAC, expiry, and replay protections.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
blockchain, payments
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.