All reports
highReentrancyEVM-Solidity

Maia DAO Ecosystem: A malicious user can set any contract as a local `hToken` for an underlying token since there is no access control for `_addLocalToken`

Payout
$0
Protocol
Maia DAO Ecosystem
Disclosed
Sep 18, 2023
Source
code4rena

A flaw in Maia DAO's cross-chain messaging mechanism allowed users to execute `_addLocalToken` on the root chain by invoking user-level `performCallOut` instead of system-enforced `performSystemCallOut`. An attacker could bypass branch-chain router checks and …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.