mediumReentrancyEVM-Solidity
Autonomint Colored Dollar V1: Reentrant call in `Treasury::withdrawFromExternalProtocol` during the `Borrowing::redeemYields` flow allows theft of `Treasury` ETH
- Payout
- $0
- Protocol
- Autonomint Colored Dollar V1
- Disclosed
- Dec 30, 2024
- Source
- sherlock
Autonomint's Borrowing::redeemYields path violates checks-effects-interactions: it sends ETH to the caller through Treasury::withdrawFromExternalProtocol using an unrestricted low-level call before burning the caller's ABOND and updating user state. A contract …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.