highLogic errorEVM-Solidity
Teller Finance: Not transferring collateral when submitting bids allows malicious users to create honeypot-style attacks
- Payout
- $0
- Protocol
- Teller Finance
- Disclosed
- Apr 29, 2024
- Source
- sherlock
Teller's peer-to-peer lending design separates bid creation from collateral transfer: submitBid only verifies the borrower's ERC-721 balance, while the actual collateral pull happens later inside lenderAcceptBid via collateralManager.deployAndDeposit. Because …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.