All reports
highSignature replayEVM-Solidity

Revert Lend: `V3Vault.sol` permit signature does not check receiving token address is USDC

Payout
$0
Protocol
Revert Lend
Disclosed
May 22, 2024
Source
code4rena

Revert Lend's V3Vault contract contains a critical input validation vulnerability regarding its use of Uniswap Permit2 for asset transfers. When performing deposits or liquidations, the contract fails to verify that the token specified in the Permit2 signature …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.