# Vulnerability found in the Timelock feature

**URL:** https://forum.tezosagora.org/t/vulnerability-found-in-the-timelock-feature/4660
**Category:** Research and Development
**Created:** [July 20, 2022, 5:26pm UTC](https://forum.tezosagora.org/t/vulnerability-found-in-the-timelock-feature/4660 "2022-07-20T17:26:11Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![NomadicLabs](https://forum.tezosagora.org/user_avatar/forum.tezosagora.org/nomadiclabs/32/763_2.png) [@NomadicLabs](https://forum.tezosagora.org/u/NomadicLabs)
#### Post date: [July 20, 2022, 5:26pm UTC](https://forum.tezosagora.org/t/vulnerability-found-in-the-timelock-feature/4660/1 "2022-07-20T17:26:11Z")

</div>

A vulnerability in the [Timelock](https://tezos.gitlab.io/active/timelock.html) cryptographic primitive was recently discovered. Having examined a recent snapshot at level [#2,548,706](https://tzkt.io/BMX7nm2mmLSzQWxxVUmgByUMy5eoLL1CNjEGoXGdsM7i24YMQtp/operations), we can confirm it does not affect any contract deployed on Tezos Mainnet.

We will publish in due time more details about this incident, how it will be fixed, and how it will be prevented from happening in the future. In the meantime, we strongly advise against the use of Timelock in Tezos smart contracts until the issue is fixed and tested.

Note that the recently injected [Kathmandu](https://research-development.nomadic-labs.com/announcing-tezos-11th-protocol-upgrade-proposal-kathmandu.html) protocol proposal, currently going through the [Tezos governance process](https://agora.tezos.com/period/76), does not address this issue.
