All reports
mediumAccess controlEVM-Solidity

MagicSea - the native DEX on the IotaEVM: Attacker can manipulate the `lockDuration` of other users positions

Payout
$0
Protocol
MagicSea - the native DEX on the IotaEVM
Disclosed
Jul 11, 2024
Source
sherlock

MagicSea's MlumStaking staking contract contained a broken authorization guard: `_requireOnlyOperatorOrOwnerOf` passed `msg.sender` as both the owner and spender arguments to OpenZeppelin's `_isAuthorized`, which returns true whenever owner equals spender, so …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.