mediumAccess controlEVM-Solidity
Rigor Protocol: Attacker can drain all the projects within minutes, if admin account has been exposed
- Payout
- $0
- Protocol
- Rigor Protocol
- Disclosed
- Aug 7, 2026
- Source
- code4rena
Rigor's HomeFi escrow protocol concentrates near-total authority in an EIP-2771 trusted forwarder: privileged admin functions and ordinary user actions both authenticate through _msgSender, so a single admin-signed (meta-)transaction obtained via a compromised …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2022-08-rigor-findings/issues/264
- https://github.com/code-423n4/2022-08-rigor-findings
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.