All reports
highFlash loan attackEVM-Solidity

NOYA: A Vault can steal all funds from another Vault through the Registry's flash loan contract due to insufficient access control in `Connector.sendTokensToTrustedAddress()`

Payout
$0
Protocol
NOYA
Disclosed
Feb 17, 2025
Source
code4rena

NOYA's `BaseConnector.sendTokensToTrustedAddress()` authorizes any caller whose address equals the Registry's shared `BalancerFlashLoan` contract, without verifying which Vault (or its keeper) initiated the flash loan. Since the flash-loan callback can direct …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.