All reports
mediumLogic errorEVM-Solidity

Napier: The pool verification in `NapierRouter` is prone to collision attacks

Payout
$0
Protocol
Napier
Disclosed
Feb 26, 2024
Source
sherlock

NapierRouter's mintCallback and swapCallback verified their caller by recomputing the CREATE2 pool address from caller-supplied basePool and underlying arguments and comparing that derived address to msg.sender. Because CREATE2 addresses truncate the keccak256 …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.