highBridge exploitEVM-Solidity
Tapioca: Unverified `_srcChainSender` parameter allows to impersonate the sender
- Payout
- $0
- Protocol
- Tapioca
- Disclosed
- Mar 15, 2024
- Source
- sherlock
Tapioca's USDO/TOFT cross-chain receiver trusts the `_srcChainSender` argument embedded in the LayerZero compose message and forwards it to downstream magnetar modules without re-validating it against the user whose position is being operated on. For several m …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.