All reports
highAccess controlEVM-Solidity

Curves Protocol: Unauthorized Access to `setCurves` Function

Payout
$0
Protocol
Curves Protocol
Disclosed
Jul 19, 2024
Source
code4rena

Curves Protocol's FeeSplitter contract exposes a public `setCurves` function with no access control, allowing any caller to repoint the fee-splitter's reference to the Curves contract at an arbitrary address. Because the fee-splitter computes `getClaimableFees …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.