All reports
mediumFlash loan attackEVM-Solidity

BakerFi: `BalancerFlashLender#receiveFlashLoan` does not validate the `originalCallData`

Payout
$0
Protocol
BakerFi
Disclosed
Jun 24, 2024
Source
code4rena

The BakerFi `BalancerFlashLender` contract contains a vulnerability where it fails to validate the `originalCallData` passed during a flash loan's `userData` parameter. Although the contract checks that the caller is the legitimate Balancer vault, it trusts th …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.