All reports
highBridge exploitEVM-Solidity

Tapioca: Unverified `_srcChainSender` parameter allows to impersonate the sender

Payout
$0
Protocol
Tapioca
Disclosed
Mar 15, 2024
Source
sherlock

Tapioca's USDO/TOFT cross-chain receiver trusts the `_srcChainSender` argument embedded in the LayerZero compose message and forwards it to downstream magnetar modules without re-validating it against the user whose position is being operated on. For several m …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.