highReentrancyEVM-Solidity
reNFT: An attacker can hijack any ERC1155 token he rents due to a design issue in reNFT via reentrancy exploitation
- Payout
- $0
- Protocol
- reNFT
- Disclosed
- Mar 20, 2024
- Source
- code4rena
reNFT routes a rented ERC1155 into the borrower's Gnosis rental safe through the Seaport conduit using safeTransferFrom, which invokes the receiver's onERC1155Receive hook — but this transfer happens before the rental is registered in the protocol's Storage mo …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-01-renft-findings/issues/588
- https://github.com/code-423n4/2024-01-renft-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.