All reports
mediumLogic errorEVM-Solidity

Gondi: Attacker can front-run and pass in empty terms, making it impossible to `confirmTerms()`

Payout
$0
Protocol
Gondi
Disclosed
Jul 25, 2024
Source
code4rena

Gondi's PoolOfferHandler stages new loan terms with an owner-only setTerms() call and later exposes a public confirmTerms() that promotes those terms after a NEW_TERMS_WAITING_TIME window. The confirmation function writes state based entirely on caller-supplie …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.