All reports
mediumAccess controlEVM-Solidity

PoolTogether: `drawManager` can be set to a malicious address

Payout
$0
Protocol
PoolTogether
Disclosed
Aug 7, 2026
Source
code4rena

The PoolTogether PrizePool contract is vulnerable to a front-running attack due to a missing access control modifier on the setDrawManager function. A malicious actor can intercept the initial setup to designate an attacker-controlled address as the draw manag …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.