All reports
highGovernance attackEVM-Solidity

Tapioca DAO: User can give himself approval for all assets held by `MagnetarV2` contract

Payout
$0
Protocol
Tapioca DAO
Disclosed
Nov 16, 2023
Source
code4rena

A high-severity input validation vulnerability in Tapioca DAO's `MagnetarV2` contract allowed arbitrary execution during permit handling. When users execute permit actions via `MagnetarV2.burst(...)`, the underlying `_permit` helper fails to check the 4-byte f …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.