highOracle manipulationEVM-Solidity
DYAD: Attacker can make `0` value `deposit()` calls to deny user from redeeming or withdrawing collateral
- Payout
- $0
- Protocol
- DYAD
- Disclosed
- Jun 17, 2024
- Source
- code4rena
The VaultManagerV2 contract contains an access control vulnerability that allows any user to perform actions on behalf of another user's collateral NFT. Because the deposit function uses an existence check rather than an ownership check, an attacker can intent …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-04-dyad-findings/issues/1001
- https://github.com/code-423n4/2024-04-dyad-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.