highGovernance attackEVM-Solidity
Governance proposal executes arbitrary call via delegatecall module
- Payout
- $350k
- Protocol
- DAO Treasury
- Disclosed
- Jun 19, 2023
- Source
- code4rena
A severe vulnerability in the governance timelock contract enabled proposal execution using DELEGATECALL without restricting the target address to a verified allowlist. Because the delegatecall target contract operated within the context of the timelock's stor …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.