All reports
highLogic errorEVM-Solidity

ZeroLend One: Malicious pool deployer can set a malicious interest rate contract to lock funds of vault depositors

Payout
$0
Protocol
ZeroLend One
Disclosed
Sep 10, 2024
Source
sherlock

ZeroLend One, an Aave-style lending protocol, permits permissionless pool deployment where the pool deployer controls the interest rate strategy contract. After vault depositors commit funds to a pool, the deployer can swap the strategy for a contract whose ca …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.