All reports
highGovernance attackEVM-Solidity

Tapioca DAO: TOFT `exerciseOption` can be used to steal all underlying erc20 tokens

Payout
$0
Protocol
Tapioca DAO
Disclosed
Nov 16, 2023
Source
code4rena

A critical input validation flaw in Tapioca DAO's BaseTOFT contract allows an attacker to steal all underlying ERC20 tokens stored within the wrapper. When executing cross-chain option redemptions via `exerciseOption` and `exerciseInternal`, parameters control …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.