All reports
highLogic errorEVM-Solidity

Tapioca: Wrong parameter in remote transfer makes it possible to steal all USDO balance from users

Payout
$0
Protocol
Tapioca
Disclosed
Mar 15, 2024
Source
sherlock

Tapioca's omnichain receiver passed the caller-supplied owner field instead of the authenticated srcChainSender when recursively building a LayerZero compose message inside _internalRemoteTransferSendPacket(). An attacker can chain several compose calls across …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.