highLogic errorEVM-Solidity
Midas: Malicious users can bypass the blacklist.
- Payout
- $0
- Protocol
- Midas
- Disclosed
- May 31, 2024
- Source
- sherlock
Midas enforces its transfer blacklist on the mTBILL token by assigning the offending address a BLACKLISTED_ROLE, checked in _beforeTokenTransfer via onlyNotBlacklisted. Because the role is granted through OpenZeppelin's AccessControlUpgradeable, any holder can …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.