All reports
highAccess controlEVM-Solidity

Maia DAO: if the Virtual Account's owner is a Contract Account (multisig wallet), attackers can gain control of the Virtual Accounts by gaining control of the same owner's address in a different chain

Payout
$0
Protocol
Maia DAO
Disclosed
Nov 29, 2023
Source
code4rena

Maia DAO's RootPort maps Virtual Accounts in the root environment solely based on the initiator's address without binding it to the source chain ID. If a user interacts with the protocol via a contract account (such as a multisig wallet) on one chain, an attac …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.