mediumLogic errorEVM-Solidity
Putty: Overlap Between `ERC721.transferFrom()` and `ERC20.transferFrom()` Allows `order.erc20Assets` or `order.baseAsset` To Be ERC721 Rather Than ERC20
- Payout
- $0
- Protocol
- Putty
- Disclosed
- Aug 7, 2026
- Source
- code4rena
Putty protocol is vulnerable to a token standard confusion issue where ERC721 tokens can be submitted in place of ERC20 assets. Because both standards share similar transferFrom function signatures, the protocol successfully pulls the NFT into its custody. How …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2022-06-putty-findings/issues/52
- https://github.com/code-423n4/2022-06-putty-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.