All reports
mediumLogic errorEVM-Solidity

Tapioca DAO: Incorrect decoding in `decodeLockTwpTapDstMsg`

Payout
$0
Protocol
Tapioca DAO
Disclosed
May 23, 2024
Source
code4rena

Tapioca's `TapTokenCodec.decodeLockTwpTapDstMsg` decodes LayerZero cross-chain lock messages by slicing the encoded payload with lengths that do not match the decoded field types. The uint96 duration field is read from a 32-byte slice instead of 12 bytes, and …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.