All reports
highAccess controlEVM-Solidity

Tapioca DAO: Adversary can steal user's NFT's if they have set Magnetar as `isApprovedForAll == true`

Payout
$0
Protocol
Tapioca DAO
Disclosed
May 23, 2024
Source
code4rena

Tapioca's Magnetar router exposes a permit-style arbitrary-call path whose selector allowlist includes IERC721.approve. The owner-parameter gate in _checkSender only verifies the decoded first address equals msg.sender, which is trivially satisfied by the call …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.