mediumLogic errorEVM-Solidity
Salty.IO: Reusing a SALT that has already been used for voting can allow a malicious proposal to pass and compromise the protocol
- Payout
- $0
- Protocol
- Salty.IO
- Disclosed
- Apr 19, 2024
- Source
- code4rena
Salty.IO's DAO vote weight is computed from the SALT currently staked in the Staking contract at the moment castVote is called, with no snapshot taken at proposal creation. That means a staker can make the same pool of SALT count as a yes-vote repeatedly on on …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-01-salty-findings/issues/844
- https://github.com/code-423n4/2024-01-salty-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.