mediumAccess controlEVM-Solidity
Velar Artha PerpDEX: Usage of `tx.origin` to determine the user is prone to attacks
- Payout
- $0
- Protocol
- Velar Artha PerpDEX
- Disclosed
- Sep 9, 2024
- Source
- sherlock
Velar Artha's perpetual-futures protocol determines the acting user in its Vyper core.vy by reading tx.origin instead of msg.sender, so any contract a user touches — unverified or upgradeable — can invoke api.vy and have the action attributed to the victim's E …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.