All reports
highReentrancyEVM-Solidity

Tapioca DAO: Reentrancy in `USDO.flashLoan()`, enabling an attacker to borrow unlimited USDO exceeding the max borrow limit

Payout
$0
Protocol
Tapioca DAO
Disclosed
Nov 16, 2023
Source
code4rena

The USDO.flashLoan() function in the Tapioca DAO protocol lacked a reentrancy guard, making it susceptible to malicious exploitation. By deploying a custom receiver contract, an attacker could trigger a reentrant call during the flash loan's execution callback …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.