All reports
mediumFront-running / MEVEVM-Solidity

Abracadabra Money: Factory::create() is vulnerable to reorg attacks

Payout
$0
Protocol
Abracadabra Money
Disclosed
May 3, 2024
Source
code4rena

Abracadabra's MIMSWAP Factory.create() derives its deterministic create2 salt solely from tx.origin and the pool's public parameters rather than from the actual caller msg.sender, so a cloned MagicLP address is a pure function of a shared EOA plus user-supplie …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.