All reports
mediumLogic errorEVM-Solidity

Panoptic: `CREATE2` address collision during pool deployment allows for complete draining of the pool

Payout
$0
Protocol
Panoptic
Disclosed
Jun 24, 2024
Source
code4rena

The Panoptic protocol allows users to supply a custom `salt` when deploying new pools via `CREATE2`, making the contract address predictable. An attacker can exploit this by brute-forcing a large number of salt values to find a collision between a future, legi …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.