The anti-slashing is not effective if the attacker can access EOTS manager endpoints.
If the EOTS manager endpoints are open to public without HMAC protection, the attacker can manually cause slashing of the finality provider through the RPC endpoints
{
"nvd_published_at": null,
"github_reviewed_at": "2025-12-12T20:15:03Z",
"cwe_ids": [
"CWE-285"
],
"severity": "HIGH",
"github_reviewed": true
}