All reports
mediumLogic errorEVM-Solidity

BendDAO: Borrower can prevent yield position repayment and closure by the bot

Payout
$0
Protocol
BendDAO
Disclosed
Sep 3, 2024
Source
code4rena

The BendDAO protocol's `_repay` function fails to account for malicious user behavior regarding ERC20 token approvals. By revoking the protocol's ability to spend their tokens, a borrower can force the repayment transaction to revert when the yield collected i …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.