All reports
mediumLogic errorEVM-Solidity

PoolTogether: `depositWithPermit` and `mintWithPermit` are allowed to be called by the permit creator only

Payout
$0
Protocol
PoolTogether
Disclosed
Aug 7, 2026
Source
code4rena

The PoolTogether vault's depositWithPermit and mintWithPermit functions incorrectly enforced that the msg.sender must be the owner of the tokens being deposited. By passing msg.sender to the permit verification process, the contract effectively disabled the ab …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.