All reports
mediumLogic errorEVM-Solidity

Rigor Protocol: In `Project.setComplete()`, the signature can be reused when the first call is reverted for some reason

Payout
$0
Protocol
Rigor Protocol
Disclosed
Aug 7, 2026
Source
code4rena

Rigor Protocol's Project.sol exposes a signature-approval lifecycle flaw: approveHash() writes only a boolean true into the approvedHashes mapping and offers no revocation path, so an approved completion hash can never be invalidated. Because of this, a subcon …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.