All reports
mediumReentrancyEVM-Solidity

Autonomint Colored Dollar V1: Reentrant call in `Treasury::withdrawFromExternalProtocol` during the `Borrowing::redeemYields` flow allows theft of `Treasury` ETH

Payout
$0
Protocol
Autonomint Colored Dollar V1
Disclosed
Dec 30, 2024
Source
sherlock

Autonomint's Borrowing::redeemYields path violates checks-effects-interactions: it sends ETH to the caller through Treasury::withdrawFromExternalProtocol using an unrestricted low-level call before burning the caller's ABOND and updating user state. A contract …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.