All reports
highOracle manipulationEVM-Solidity

DYAD: Attacker can make `0` value `deposit()` calls to deny user from redeeming or withdrawing collateral

Payout
$0
Protocol
DYAD
Disclosed
Jun 17, 2024
Source
code4rena

The VaultManagerV2 contract contains an access control vulnerability that allows any user to perform actions on behalf of another user's collateral NFT. Because the deposit function uses an existence check rather than an ownership check, an attacker can intent …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.