All reports
mediumAccess controlEVM-Solidity

Velar Artha PerpDEX: Usage of `tx.origin` to determine the user is prone to attacks

Payout
$0
Protocol
Velar Artha PerpDEX
Disclosed
Sep 9, 2024
Source
sherlock

Velar Artha's perpetual-futures protocol determines the acting user in its Vyper core.vy by reading tx.origin instead of msg.sender, so any contract a user touches — unverified or upgradeable — can invoke api.vy and have the action attributed to the victim's E …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.