highAccess controlEVM-Solidity
Tapioca: Unprotected `executeModule` function allows to steal the tokens
- Payout
- $0
- Protocol
- Tapioca
- Disclosed
- Mar 15, 2024
- Source
- sherlock
Tapioca's USDO token exposes a public executeModule function whose module selector and encoded parameters are entirely caller-controlled with no ownership or authorization check. Because the function forwards arbitrary module calls (here UsdoMarketReceiver.rem …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.