highLogic errorEVM-Solidity
Tapioca: Wrong parameter in remote transfer makes it possible to steal all USDO balance from users
- Payout
- $0
- Protocol
- Tapioca
- Disclosed
- Mar 15, 2024
- Source
- sherlock
Tapioca's omnichain receiver passed the caller-supplied owner field instead of the authenticated srcChainSender when recursively building a LayerZero compose message inside _internalRemoteTransferSendPacket(). An attacker can chain several compose calls across …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.