highLogic errorEVM-Solidity
ZeroLend One: Malicious pool deployer can set a malicious interest rate contract to lock funds of vault depositors
- Payout
- $0
- Protocol
- ZeroLend One
- Disclosed
- Sep 10, 2024
- Source
- sherlock
ZeroLend One, an Aave-style lending protocol, permits permissionless pool deployment where the pool deployer controls the interest rate strategy contract. After vault depositors commit funds to a pool, the deployer can swap the strategy for a contract whose ca …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.