All reports
highAccess controlEVM-Solidity

Maia DAO: All tokens can be stolen from `VirtualAccount` due to missing access modifier

Payout
$0
Protocol
Maia DAO
Disclosed
Nov 29, 2023
Source
code4rena

A missing authorization modifier in Maia DAO's `VirtualAccount` contract allowed any arbitrary external caller to execute unauthorized functions. While `call()` correctly enforced `requiresApprovedCaller`, the adjacent `payableCall()` function omitted this che …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.