highReentrancyEVM-Solidity
NextGen: Attacker can drain all ETH from `AuctionDemo` when `block.timestamp == auctionEndTime`
- Payout
- $0
- Protocol
- NextGen
- Disclosed
- Jan 8, 2024
- Source
- code4rena
The NextGen AuctionDemo contract is vulnerable to a reentrancy attack that allows for the drainage of ETH and the theft of NFTs. The flaw occurs because the contract fails to update the bid status before executing an external transfer of funds to the winner. B …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-10-nextgen-findings/issues/1323
- https://github.com/code-423n4/2023-10-nextgen-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.