mediumAccess controlEVM-Solidity
MagicSea - the native DEX on the IotaEVM: Attacker can manipulate the `lockDuration` of other users positions
- Payout
- $0
- Protocol
- MagicSea - the native DEX on the IotaEVM
- Disclosed
- Jul 11, 2024
- Source
- sherlock
MagicSea's MlumStaking staking contract contained a broken authorization guard: `_requireOnlyOperatorOrOwnerOf` passed `msg.sender` as both the owner and spender arguments to OpenZeppelin's `_isAuthorized`, which returns true whenever owner equals spender, so …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.