highAccess controlEVM-Solidity
Arrakis Valantis SOT: A malicious executor can delete the fees belonging to the owner of `ArrakisStandardManager`
- Payout
- $0
- Protocol
- Arrakis Valantis SOT
- Disclosed
- Jun 4, 2024
- Source
- sherlock
In the Arrakis/Valantis SOT integration, the executor role on ArrakisStandardManager is supposed to be restricted during a vault rebalance, but the ValantisHOTModule's swap() path hands the caller an arbitrary call target. Because the module itself holds the p …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.