CVE-2018-10376: Smartmesh

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _fee and _value parameters, as exploited in the wild in April 2018, aka the "proxyOverflow" issue.

Affected products

  • Smartmesh Smartmesh: affected versions not specified

Published 2018-04-25. Last modified 2026-06-17.