All reports
highLogic errorEVM-Solidity

DittoETH: An attacker can cancel other people's short orders

Payout
$0
Protocol
DittoETH
Disclosed
Jun 25, 2024
Source
code4rena

DittoETH's LibSRUtil.transferShortRecord cancels the short order referenced by nft.shortOrderId without first verifying that the order still belongs to the NFT's owner. Because short order ids are reused after an order is cancelled and its record deleted, an a …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.