mediumLogic errorEVM-Solidity
Rigor Protocol: In `Project.setComplete()`, the signature can be reused when the first call is reverted for some reason
- Payout
- $0
- Protocol
- Rigor Protocol
- Disclosed
- Aug 7, 2026
- Source
- code4rena
Rigor Protocol's Project.sol exposes a signature-approval lifecycle flaw: approveHash() writes only a boolean true into the approvedHashes mapping and offers no revocation path, so an approved completion hash can never be invalidated. Because of this, a subcon …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2022-08-rigor-findings/issues/263
- https://github.com/code-423n4/2022-08-rigor-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.