mediumAccess controlSolana-Rust
DODO Cross-Chain DEX: Bug in AccountEncoder causes wrong Solana account permissions
- Payout
- $0
- Protocol
- DODO Cross-Chain DEX
- Disclosed
- Jun 9, 2025
- Source
- sherlock
DODO's cross-chain bridge compresses Solana account permissions into a byte array in its EVM-side AccountEncoder library. The decompressAccounts() assembly routine reads a full 32-byte word with mload when parsing what should be a single 1-byte isWritable bool …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.