All reports
mediumReentrancyOther

Kakarot: Reentrancy check in `account_contract` can be easily circumvented

Payout
$0
Protocol
Kakarot
Disclosed
Dec 10, 2024
Source
code4rena

Kakarot, a Cairo-based zk-EVM running on Starknet, guarded its account_contract.execute_starknet_call against reentrancy by only blocking calls to Kakarot's own address when the selector was anything other than the harmless get_starknet_address getter. An atta …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.