mediumLogic errorEVM-Solidity
BendDAO: Borrower can prevent yield position repayment and closure by the bot
- Payout
- $0
- Protocol
- BendDAO
- Disclosed
- Sep 3, 2024
- Source
- code4rena
The BendDAO protocol's `_repay` function fails to account for malicious user behavior regarding ERC20 token approvals. By revoking the protocol's ability to spend their tokens, a borrower can force the repayment transaction to revert when the yield collected i …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-07-benddao-findings/issues/9
- https://github.com/code-423n4/2024-07-benddao-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.