All reports
mediumOracle manipulationEVM-Solidity

Salty.IO: Adversary can prevent updating price feed addresses by creating poisonous proposals ending in `_confirm`

Payout
$0
Protocol
Salty.IO
Disclosed
Apr 19, 2024
Source
code4rena

The Salty.IO protocol's DAO governance mechanism was vulnerable to a denial-of-service attack due to predictable ballot naming conventions. By creating proposals with a specific '_confirm' suffix, attackers could block legitimate administrative actions, includ …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.