All reports
highLogic errorEVM-Solidity

Axis Finance: Malicious user can overtake a prefunded auction and steal the deposited funds

Payout
$0
Protocol
Axis Finance
Disclosed
Mar 30, 2024
Source
sherlock

Axis Finance's Auctioneer.auction() writes routing details to lotRouting[lotId] using a storage reference bound before lotId is actually assigned; because the return-value variable initially holds 0, the reference always points to lotRouting[0]. An attacker wh …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.