highLogic errorEVM-Solidity
INIT Capital: wLp tokens could be stolen
- Payout
- $0
- Protocol
- INIT Capital
- Disclosed
- Jan 16, 2024
- Source
- code4rena
The INIT Capital protocol contained a critical logic flaw in its PosManager contract that allowed unauthorized users to drain wrapped LP (wLp) collateral from arbitrary positions. The vulnerability stemmed from an incomplete ownership validation check in the r …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-12-initcapital-findings/issues/31
- https://github.com/code-423n4/2023-12-initcapital-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.